Vulnerability record · CVE-2017-17411 · published 21 December 2017
CVE-2017-17411: Linksys WVBR0 web portal OS command injection allows unauthenticated root code execution
Linksys · Wvbr0 Firmware
CVE-2017-17411 is an OS command injection (CWE-78) in the web management portal of Linksys WVBR0 firmware. User-supplied data is passed to a system call without proper validation, letting a remote attacker run commands as root. Because no authentication is required, any network-reachable instance is exposed.
Description
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a system call. An attacker could leverage this vulnerability to execute code with root privileges. Was ZDI-CAN-4892.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command execution as root with public exploit code and very high EPSS probability.
What it is
CVE-2017-17411 is an OS command injection (CWE-78) in the web management portal of Linksys WVBR0 firmware. User-supplied data is passed to a system call without proper validation, letting a remote attacker run commands as root. Because no authentication is required, any network-reachable instance is exposed.
Impact
An attacker gains arbitrary command execution with root privileges on the device, allowing full compromise of the router and any traffic or credentials it handles.
Attack surface
Reached over the network through the web management portal (CVSS AV:N, PR:N, UI:N); no authentication or user interaction is needed.
Exploitation
Public exploit code exists (Metasploit PR and Exploit-DB entries), and EPSS is 0.87929 (99.755th percentile), though the CVE is not listed in CISA KEV.
What to do
- Apply the vendor firmware update for Linksys WVBR0; if none is available, replace or retire the device.
- Remove the web management portal from untrusted networks and restrict administrative access to a dedicated management VLAN or trusted hosts.
- Block external access to the device's web management interface at the firewall or edge.
- If the portal cannot be disabled or isolated, power down or replace the affected unit.
Detection
- Monitor device and perimeter logs for HTTP requests to the WVBR0 web management portal from untrusted sources.
- Inspect for shell metacharacters or command strings in requests to the portal's management endpoints.
- Watch for unexpected outbound connections or processes spawned by the device's web service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/102212 | Third Party AdvisoryVDB Entry |
| https://github.com/rapid7/metasploit-framework/pull/9336 | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/43363/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/43429/ | ExploitThird Party AdvisoryVDB Entry |
| https://zerodayinitiative.com/advisories/ZDI-17-973 | Third Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/102212 | Third Party AdvisoryVDB Entry |
| https://github.com/rapid7/metasploit-framework/pull/9336 | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/43363/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/43429/ | ExploitThird Party AdvisoryVDB Entry |
| https://zerodayinitiative.com/advisories/ZDI-17-973 | Third Party AdvisoryVDB Entry |
Track CVE-2017-17411 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-17411), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.