CVE-2014-8243: Linksys e4200v2
Low severity, CVSS 3.3. EPSS: 1.2% chance of exploitation in the next 30 days.
Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain the administrator's MD5 password hash via a direct request for the /.htpasswd URI.
Affected products
- Linksys e4200v2
- Linksys e4200v2 Firmware: up to and including 2.0.14212.1
- Linksys EA2700
- Linksys EA2700 Firmware: up to and including 2.0.14294
- Linksys EA3500
- Linksys EA3500 Firmware: up to and including 2.0.14294
- Linksys EA4500
- Linksys EA4500 Firmware: up to and including 2.0.14212.1
- Linksys EA6200
- Linksys EA6200 Firmware: up to and including 1.1.41
- Linksys EA6300
- Linksys EA6300 Firmware: up to and including 1.1.40
- Linksys EA6400
- Linksys EA6400 Firmware: up to and including 1.1.40
- Linksys EA6500
- Linksys EA6500 Firmware: up to and including 1.1.40
- Linksys EA6700
- Linksys EA6700 Firmware: up to and including 1.1.40
- Linksys EA6900
- Linksys EA6900 Firmware: up to and including 1.1.42
Published 2014-11-01. Last modified 2026-06-17.