CVE-2022-38132
Published on: Not Yet Published
Last Modified on: 08/29/2022 03:52:00 PM UTC
Certain versions of Mr8300 from Linksys contain the following vulnerability:
Command injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By specifying username and password, an attacker connected to the router's web interface can execute arbitrary OS commands. The username and password fields are not sanitized correctly and are used as URL construction arguments, allowing URL redirection to an arbitrary server, downloading an arbitrary script file, and eventually executing the file in the device. This issue affects: Linksys MR8300 Router 1.0.
- CVE-2022-38132 has been assigned by
in[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Linksys - MR8300 Router version = 1.0
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
downloads.linksys.com text/plain |
![]() |
Exploit/POC from Github
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file i…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Linksys | Mr8300 | - | All | All | All |
Operating System | Linksys | Mr8300 Firmware | 1.0 | All | All | All |
- cpe:2.3:h:linksys:mr8300:-:*:*:*:*:*:*:*:
- cpe:2.3:o:linksys:mr8300_firmware:1.0:*:*:*:*:*:*:*:
Discovery Credit
Cybellum Technologies LTD.
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-38132 : Command injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By sp… twitter.com/i/web/status/1… | 2022-08-23 23:26:40 |
![]() |
Potentially Critical CVE Detected! CVE-2022-38132 Command injection vulnerability in Linksys MR8300 router while Re… twitter.com/i/web/status/1… | 2022-08-24 01:56:01 |
![]() |
CVE-2022-38132 | 2022-08-24 00:38:35 |