Linksys WVBR0-25 User-Agent Command Execution

cve CVE-2017-17411 2 sources, 3 claims · Watch

Metasploit exploit modules writes:
The Linksys WVBR0-25 Wireless Video Bridge, used by DirecTV to connect wireless Genie cable boxes to the Genie DVR, is vulnerable to OS command injection in version < 1.0.41 of the web management portal via the User-Agent header. Authentication is not required to exploit this vulnerability. the claim

What each source says

PropertySourceSaidMeans here
Author
author
Exploit-DBMetasploit
receipt
Source
Exploit-DB
Its words
Metasploit
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-03 00:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2017-17411",
  "date_added": "2018-01-04",
  "date_published": "2018-01-04",
  "date_updated": "2018-01-04",
  "description": "Linksys WVBR0-25 - User-Agent Command Execution (Metasploit)",
  "file": "exploits/hardware/remote/43429.rb",
  "id": "43429",
  "platform": "hardware",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/c3f10c1d57f614d10035028a3343458a6e5011b9/modules/exploits/linux/http/linksys_wvbr0_user_agent_exec_noauth.rb",
  "tags": "Metasploit Framework (MSF)",
  "type": "remote",
  "verified": "0"
}
—
Author
author
nixawk
receipt
Source
Exploit-DB
Its words
nixawk
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-03 00:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "nixawk",
  "codes": "CVE-2017-17411",
  "date_added": "2017-12-18",
  "date_published": "2017-12-14",
  "date_updated": "2017-12-18",
  "description": "Linksys WVBR0 - 'User-Agent' Remote Command Injection",
  "file": "exploits/hardware/webapps/43363.py",
  "id": "43363",
  "platform": "hardware",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://github.com/nixawk/labs/blob/5777612e4a7d06f4e1811ca654bcb22c050078bf/CVE-2017-17411/exploit-CVE-2017-17411.py",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Platform
platform
not compared
Exploit-DBhardware
receipt
Source
Exploit-DB
Its words
hardware
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-03 00:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2017-17411",
  "date_added": "2018-01-04",
  "date_published": "2018-01-04",
  "date_updated": "2018-01-04",
  "description": "Linksys WVBR0-25 - User-Agent Command Execution (Metasploit)",
  "file": "exploits/hardware/remote/43429.rb",
  "id": "43429",
  "platform": "hardware",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/c3f10c1d57f614d10035028a3343458a6e5011b9/modules/exploits/linux/http/linksys_wvbr0_user_agent_exec_noauth.rb",
  "tags": "Metasploit Framework (MSF)",
  "type": "remote",
  "verified": "0"
}
—
Platform
platform
not compared
Metasploit exploit modulesUnix
receipt
Source
Metasploit exploit modules
Its words
Unix
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-03 04:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd",
  "author": [
    "HeadlessZeke"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "The Linksys WVBR0-25 Wireless Video Bridge, used by DirecTV to connect wireless Genie\n          cable boxes to the Genie DVR, is vulnerable to OS command injection in version < 1.0.41\n          of the web management portal via the User-Agent header. Authentication is not required to\n          exploit this vulnerability.",
  "disclosure_date": "2017-12-13",
  "fullname": "exploit/linux/http/linksys_wvbr0_user_agent_exec_noauth",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:54:55 +0000",
  "name": "Linksys WVBR0-25 User-Agent Command Execution",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "unknown-reliability"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "unknown-stability"
    ]
  },
  "path": "/modules/exploits/linux/http/linksys_wvbr0_user_agent_exec_noauth.rb",
  "platform": "Unix",
  "post_auth": false,
  "rank": 600,
  "ref_name": "linux/http/linksys_wvbr0_user_agent_exec_noauth",
  "references": [
    "CVE-2017-17411",
    "ZDI-17-973",
    "URL-https://www.thezdi.com/blog/2017/12/13/remote-root-in-directvs-wireless-video-bridge-a-tale-of-rage-and-despair"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "Automatic"
  ],
  "type": "exploit"
}
—
Rank
rank
Metasploit exploit modules600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-03 04:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd",
  "author": [
    "HeadlessZeke"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "The Linksys WVBR0-25 Wireless Video Bridge, used by DirecTV to connect wireless Genie\n          cable boxes to the Genie DVR, is vulnerable to OS command injection in version < 1.0.41\n          of the web management portal via the User-Agent header. Authentication is not required to\n          exploit this vulnerability.",
  "disclosure_date": "2017-12-13",
  "fullname": "exploit/linux/http/linksys_wvbr0_user_agent_exec_noauth",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:54:55 +0000",
  "name": "Linksys WVBR0-25 User-Agent Command Execution",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "unknown-reliability"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "unknown-stability"
    ]
  },
  "path": "/modules/exploits/linux/http/linksys_wvbr0_user_agent_exec_noauth.rb",
  "platform": "Unix",
  "post_auth": false,
  "rank": 600,
  "ref_name": "linux/http/linksys_wvbr0_user_agent_exec_noauth",
  "references": [
    "CVE-2017-17411",
    "ZDI-17-973",
    "URL-https://www.thezdi.com/blog/2017/12/13/remote-root-in-directvs-wireless-video-bridge-a-tale-of-rage-and-despair"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "Automatic"
  ],
  "type": "exploit"
}
—
Type
type
Exploit-DBremote
receipt
Source
Exploit-DB
Its words
remote
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-03 00:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2017-17411",
  "date_added": "2018-01-04",
  "date_published": "2018-01-04",
  "date_updated": "2018-01-04",
  "description": "Linksys WVBR0-25 - User-Agent Command Execution (Metasploit)",
  "file": "exploits/hardware/remote/43429.rb",
  "id": "43429",
  "platform": "hardware",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/c3f10c1d57f614d10035028a3343458a6e5011b9/modules/exploits/linux/http/linksys_wvbr0_user_agent_exec_noauth.rb",
  "tags": "Metasploit Framework (MSF)",
  "type": "remote",
  "verified": "0"
}
—
Type
type
webapps
receipt
Source
Exploit-DB
Its words
webapps
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-03 00:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "nixawk",
  "codes": "CVE-2017-17411",
  "date_added": "2017-12-18",
  "date_published": "2017-12-14",
  "date_updated": "2017-12-18",
  "description": "Linksys WVBR0 - 'User-Agent' Remote Command Injection",
  "file": "exploits/hardware/webapps/43363.py",
  "id": "43363",
  "platform": "hardware",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://github.com/nixawk/labs/blob/5777612e4a7d06f4e1811ca654bcb22c050078bf/CVE-2017-17411/exploit-CVE-2017-17411.py",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Verified
verified
Exploit-DBfalse
receipt
Source
Exploit-DB
Its words
0
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-03 00:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2017-17411",
  "date_added": "2018-01-04",
  "date_published": "2018-01-04",
  "date_updated": "2018-01-04",
  "description": "Linksys WVBR0-25 - User-Agent Command Execution (Metasploit)",
  "file": "exploits/hardware/remote/43429.rb",
  "id": "43429",
  "platform": "hardware",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/c3f10c1d57f614d10035028a3343458a6e5011b9/modules/exploits/linux/http/linksys_wvbr0_user_agent_exec_noauth.rb",
  "tags": "Metasploit Framework (MSF)",
  "type": "remote",
  "verified": "0"
}
—

exploit

Linksys WVBR0-25 User-Agent Command Execution
zetlyn/cve-metasploit · 2017-12-13
platform Unix rank 600 source
Linksys WVBR0-25 - User-Agent Command Execution (Metasploit)
zetlyn/cve-exploitdb · 2018-01-04
author Metasploit platform hardware type remote verified false source
Linksys WVBR0 - 'User-Agent' Remote Command Injection
zetlyn/cve-exploitdb · 2017-12-14
author nixawk platform hardware type webapps verified false source