Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file's existence or otherwise access that file.
Link | Tags |
---|---|
https://downloads.linksys.com/support/assets/releasenotes/WHW01_VLP01_1.1.13.202617_Customer_Release_Notes.txt | release notes |
https://github.com/IvanGlinkin/CVE-2024-36821 | third party advisory exploit |