CVE-2020-35713

CRITICAL WAF: High
CVSS 9.8 Published: 2020-12-26
CWE-78

Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
linksysre6500_firmwareup to 1.0.012.001

References

Back to CVE Database