Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hqr4-jx9c-hhxr

Опубликовано: 21 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 3.9

Описание

In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

EPSS

Процентиль: 2%
0.00015
Низкий

3.9 Low

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 3.9
nvd
7 месяцев назад

In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

EPSS

Процентиль: 2%
0.00015
Низкий

3.9 Low

CVSS3

Дефекты

CWE-284