CVE-2018-17208 is an unauthenticated command injection vulnerability affecting Linksys Velop 1.1.2.187020 devices, allowing attackers to gain full root access through mishandling of shell metacharacters in specific CGI scripts. This high-severity vulnerability (CVSS 8.8) can be exploited remotely with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability, and can also be triggered via CSRF. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.2.187020CPE matchmatch criteria | cpe:2.3:o:linksys:velop_firmware:1.1.2.187020:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.