CVE-2024-57225: Command Injection
Published Jan 10, 2025
·Updated
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the resetwifi function.
Affected Software
3 affected components
LinkSys E7350
All of the following
LinkSys E7350 Firmware=1.1.00.032
LinkSys E7350
Event History
Jan 10, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-57225?
CVE-2024-57225 has been classified as a high-severity vulnerability due to its potential to allow unauthorized command execution.
2
How do I fix CVE-2024-57225?
To fix CVE-2024-57225, update your Linksys E7350 firmware to the latest version provided by the manufacturer.
3
What products are affected by CVE-2024-57225?
CVE-2024-57225 specifically affects the Linksys E7350 router running firmware version 1.1.00.032.
4
What type of vulnerability is CVE-2024-57225?
CVE-2024-57225 is identified as a command injection vulnerability that can be exploited via the devname parameter.
5
How can attackers exploit CVE-2024-57225?
Attackers can exploit CVE-2024-57225 by sending crafted requests to the reset_wifi function, potentially executing arbitrary commands on the device.