{"api_version":"1","generated_at":"2026-07-23T22:22:14+00:00","cve":"CVE-2017-17411","urls":{"html":"https://cve.report/CVE-2017-17411","api":"https://cve.report/api/cve/CVE-2017-17411.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-17411","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-17411"},"summary":{"title":"CVE-2017-17411","description":"This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a system call. An attacker could leverage this vulnerability to execute code with root privileges. Was ZDI-CAN-4892.","state":"PUBLISHED","assigner":"zdi","published_at":"2017-12-21 14:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-78","CWE-78 CWE-78-Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://github.com/rapid7/metasploit-framework/pull/9336","name":"https://github.com/rapid7/metasploit-framework/pull/9336","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"],"title":"Adds exploit module for CVE-2017-17411 by headlesszeke · Pull Request #9336 · rapid7/metasploit-framework · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/43363/","name":"https://www.exploit-db.com/exploits/43363/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Linksys WVBR0 - 'User-Agent' Remote Command Injection","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://zerodayinitiative.com/advisories/ZDI-17-973","name":"https://zerodayinitiative.com/advisories/ZDI-17-973","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/43429/","name":"https://www.exploit-db.com/exploits/43429/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Linksys WVBR0-25 - User-Agent Command Execution (Metasploit) - Hardware remote Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/102212","name":"http://www.securityfocus.com/bid/102212","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Linksys WVBR0-25 CVE-2017-17411 Remote Command Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-17411","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-17411","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linksys","product":"Linksys WVBR0","version":"affected WVBR0","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"17411","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"linksys","cpe5":"wvbr0","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"17411","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linksys","cpe5":"wvbr0_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2017","cve_id":"17411","cve":"CVE-2017-17411","epss":"0.921610000","percentile":"0.997210000","score_date":"2026-05-19","updated_at":"2026-05-20 00:11:25"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T20:51:31.306Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"102212","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/102212"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/rapid7/metasploit-framework/pull/9336"},{"name":"43363","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/43363/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://zerodayinitiative.com/advisories/ZDI-17-973"},{"name":"43429","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/43429/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Linksys WVBR0","vendor":"Linksys","versions":[{"status":"affected","version":"WVBR0"}]}],"datePublic":"2017-12-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a system call. An attacker could leverage this vulnerability to execute code with root privileges. Was ZDI-CAN-4892."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-78","description":"CWE-78-Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2018-08-28T20:57:01.000Z","orgId":"99f1926a-a320-47d8-bbb5-42feb611262e","shortName":"zdi"},"references":[{"name":"102212","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/102212"},{"tags":["x_refsource_MISC"],"url":"https://github.com/rapid7/metasploit-framework/pull/9336"},{"name":"43363","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/43363/"},{"tags":["x_refsource_MISC"],"url":"https://zerodayinitiative.com/advisories/ZDI-17-973"},{"name":"43429","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/43429/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"zdi-disclosures@trendmicro.com","ID":"CVE-2017-17411","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Linksys WVBR0","version":{"version_data":[{"version_value":"WVBR0"}]}}]},"vendor_name":"Linksys"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a system call. An attacker could leverage this vulnerability to execute code with root privileges. Was ZDI-CAN-4892."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-78-Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}]}]},"references":{"reference_data":[{"name":"102212","refsource":"BID","url":"http://www.securityfocus.com/bid/102212"},{"name":"https://github.com/rapid7/metasploit-framework/pull/9336","refsource":"MISC","url":"https://github.com/rapid7/metasploit-framework/pull/9336"},{"name":"43363","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/43363/"},{"name":"https://zerodayinitiative.com/advisories/ZDI-17-973","refsource":"MISC","url":"https://zerodayinitiative.com/advisories/ZDI-17-973"},{"name":"43429","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/43429/"}]}}}},"cveMetadata":{"assignerOrgId":"99f1926a-a320-47d8-bbb5-42feb611262e","assignerShortName":"zdi","cveId":"CVE-2017-17411","datePublished":"2017-12-21T14:00:00.000Z","dateReserved":"2017-12-05T00:00:00.000Z","dateUpdated":"2024-08-05T20:51:31.306Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-12-21 14:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-78","CWE-78 CWE-78-Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linksys:wvbr0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.0.41","matchCriteriaId":"89C14B79-5C23-4DF4-8607-C5B14DAC75EF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:linksys:wvbr0:-:*:*:*:*:*:*:*","matchCriteriaId":"B1129E8A-FAF1-4B2D-829C-B01DC003F04C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"17411","Ordinal":"1","Title":"CVE-2017-17411","CVE":"CVE-2017-17411","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"17411","Ordinal":"1","NoteData":"This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a system call. An attacker could leverage this vulnerability to execute code with root privileges. Was ZDI-CAN-4892.","Type":"Description","Title":"CVE-2017-17411"},{"CveYear":"2017","CveId":"17411","Ordinal":"2","NoteData":"2017-12-21","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"17411","Ordinal":"3","NoteData":"2018-08-28","Type":"Other","Title":"Modified"}]}}}