CVE-2024-36821
11.06.2024, 18:15
Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root.Enginsight
Vendor | Product | Version |
---|---|---|
linksys | velop_whw0101_firmware | 1.1.13.202617 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-732 - Incorrect Permission Assignment for Critical ResourceThe product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
- CWE-379 - Creation of Temporary File in Directory with Insecure PermissionsThe software creates a temporary file in a directory whose permissions allow unintended actors to determine the file's existence or otherwise access that file.
References