CVE-2024-57222: Command Injection
Published Jan 10, 2025
·Updated
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apclicancelwps function.
Affected Software
3 affected components
LinkSys E7350
All of the following
LinkSys E7350 Firmware=1.1.00.032
LinkSys E7350
Event History
Jan 10, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-57222?
CVE-2024-57222 is classified as a high severity vulnerability due to the potential for remote command injection.
2
How do I fix CVE-2024-57222?
To mitigate CVE-2024-57222, users should update the Linksys E7350 device to the latest firmware version provided by Linksys.
3
What is the impact of CVE-2024-57222?
The impact of CVE-2024-57222 allows attackers to execute arbitrary commands on the affected Linksys E7350 device.
4
Who is affected by CVE-2024-57222?
Users of the Linksys E7350 router with firmware version 1.1.00.032 are affected by CVE-2024-57222.
5
What component is vulnerable in CVE-2024-57222?
The vulnerability in CVE-2024-57222 is located within the apcli_cancel_wps function, specifically through the ifname parameter.