Linksys RE6500 UNAUTHENTICATED RCE working across multiple FW versions.

Disclosed by
RE-Solver's avatar
RE-Solver
  • Engagement Undisclosed
  • Disclosed date over 4 years ago
  • Points 40
  • Priority P1 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by customer

The unauthenticated RCE issue for the Linksys RE6500 has been resolved and we urge all customers using this product to update to the latest firmware (available here: https://www.linksys.com/us/support-article?articleNum=148460). Thank you to @RE-Solver for bringing this issue to our attention.

Summary by RE-Solver

I do request for a CVE assignment and public disclosure on my blog with the POC.

Activity
  1. belkin-international-inc_1499’s avatar
    belkin-international-inc_1499 Customer resolved a blocker for Belkin International, Inc. by providing information on impact

    ()

  2. belkin-international-inc_1499’s avatar
    belkin-international-inc_1499 Customer changed the state to Resolved

    ()

  3. belkin-international-inc_1499’s avatar
    belkin-international-inc_1499 Customer rewarded RE-Solver 40 points

    ()

  4. belkin-international-inc_1499’s avatar
    belkin-international-inc_1499 Customer published the disclosure report

    ()

  5. belkin-international-inc_1499’s avatar
    belkin-international-inc_1499 Customer changed the state to Triaged

    ()

  6. shpendk_bugcrowd’s avatarbugcrowd logo
    shpendk_bugcrowd created a blocker on Belkin International, Inc. to provide information on impact

    ()

  7. RE-Solver’s avatar
    RE-Solver sent a message

    ()

  8. belkin-international-inc_1499’s avatar
    belkin-international-inc_1499 Customer resolved a blocker for Belkin International, Inc. by providing information on impact

    ()

  9. belkin-international-inc_1499’s avatar
    belkin-international-inc_1499 Customer sent a message

    ()

  10. RE-Solver’s avatar
    RE-Solver sent a message

    ()

  11. ulas_bugcrowd’s avatarbugcrowd logo
    ulas_bugcrowd created a blocker on Belkin International, Inc. to provide information on impact

    ()

  12. RE-Solver’s avatar
    RE-Solver sent a message

    ()

  13. belkin-international-inc_1499’s avatar
    belkin-international-inc_1499 Customer resolved a blocker for Bugcrowd Operations by providing information on impact

    ()

  14. belkin-international-inc_1499’s avatar
    belkin-international-inc_1499 Customer sent a message

    ()

  15. RE-Solver’s avatar
    RE-Solver requested disclosure

    ()

  16. Raven_Bugcrowd’s avatarbugcrowd logo
    Raven_Bugcrowd created a blocker on Belkin International, Inc. to provide information on impact

    ()

  17. RE-Solver’s avatar
    RE-Solver sent a message

    ()

  18. belkin-international-inc_1499’s avatar
    belkin-international-inc_1499 Customer resolved a blocker for Bugcrowd Operations by providing information on impact

    ()

  19. belkin-international-inc_1499’s avatar
    belkin-international-inc_1499 Customer sent a message

    ()

  20. Raven_Bugcrowd’s avatarbugcrowd logo
    Raven_Bugcrowd created a blocker on Belkin International, Inc. to provide information on impact

    ()

  21. RE-Solver’s avatar
    RE-Solver sent a message

    ()

  22. RE-Solver’s avatar
    RE-Solver claimed the submission

    ()

  23. belkin-international-inc_1499’s avatar
    belkin-international-inc_1499 Customer sent a message

    ()

  24. External Submission Form’s avatar
    External Submission Form created the submission

    ()