Back

HIGH

Linksys Routers apply.cgi Remote Command Injection

Published Aug 1, 2025

Description

An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) running firmware version v2.0.03 via the apply.cgi endpoint. The web interface fails to properly sanitize user-supplied input passed to the ping_size parameter during diagnostic operations. An attacker with valid credentials can inject arbitrary shell commands, enabling remote code execution.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 1, 2025
Updated Apr 7, 2026
Reserved Aug 1, 2025
CISA Vulnrichment
Updated Aug 6, 2025
NVD
Status Deferred
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Aug 1, 2025
Updated Apr 7, 2026
Exploited since n/a
EUVD-2013-7268