CVE-2024-57224: Command Injection
Published Jan 10, 2025
·Updated
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apclidoenrpinwps function.
Affected Software
3 affected components
LinkSys E7350
All of the following
LinkSys E7350 Firmware=1.1.00.032
LinkSys E7350
Event History
Jan 10, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-57224?
CVE-2024-57224 has a high severity due to its potential to allow command injection on the Linksys E7350.
2
How do I fix CVE-2024-57224?
To fix CVE-2024-57224, update the Linksys E7350 firmware to the latest version released by Linksys.
3
Who is affected by CVE-2024-57224?
Users of the Linksys E7350 running version 1.1.00.032 are affected by CVE-2024-57224.
4
What is a command injection vulnerability in the context of CVE-2024-57224?
In the context of CVE-2024-57224, a command injection vulnerability allows an attacker to execute arbitrary commands on the system via manipulated input.
5
Is there a patch available for CVE-2024-57224?
Yes, there is a patch available which can be obtained by upgrading the Linksys E7350 to the latest firmware version.