VYPR

Velop Firmware

by Linksys

CVEs (1)

  • CVE-2018-17208HigSep 19, 2018
    risk 0.57cvss 8.8epss 0.03

    Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cgi-bin/zbtest2.cgi (scripts that can be discovered with binwalk on the firmware, but are not visible in the web interface). This…