CVE-2024-57223: Command Injection
Published Jan 10, 2025
·Updated
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcliwpsgenpincode function.
Affected Software
3 affected components
LinkSys E7350
All of the following
LinkSys E7350 Firmware=1.1.00.032
LinkSys E7350
Event History
Jan 10, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-57223?
CVE-2024-57223 has a critical severity rating due to the command injection vulnerability it poses.
2
How do I fix CVE-2024-57223?
To fix CVE-2024-57223, update your Linksys E7350 router to the latest firmware version provided by Linksys.
3
What is the impact of CVE-2024-57223?
The impact of CVE-2024-57223 can allow an attacker to execute arbitrary commands on the affected device.
4
Is my Linksys E7350 affected by CVE-2024-57223?
Yes, Linksys E7350 with firmware version 1.1.00.032 is affected by CVE-2024-57223.
5
What is the exploit technique used in CVE-2024-57223?
CVE-2024-57223 is exploited through command injection via the ifname parameter in the apcli_wps_gen_pincode function.