VYPR
Vendor

Linksys

Linksys Holdings, Inc., is an English brand of data networking hardware products mainly sold to home users and small businesses. It was founded in 1988 by the couple Victor and Janie Tsao, both Taiwanese immigrants to the United States. Linksys products include Wi-Fi routers, mesh Wi-Fi systems, Wifi extenders, access points, network switches, and Wi-Fi networking. It is headquartered in Irvine, California.

Founded 1988
Products
175
CVEs
246
Across products
738
Status
Private

Products

175
View all 175 products →

Recent CVEs

246
View all 246 CVEs →
  • CVE-2025-34037CriJun 24, 2025
    risk 0.75cvss epss 0.86

    An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization,…

  • CVE-2017-17411CriDec 21, 2017
    risk 0.74cvss 9.8epss 0.88

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper…

  • CVE-2013-2681CriFeb 5, 2020
    risk 0.68cvss 9.8epss 0.10

    Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.

  • CVE-2020-35713CriDec 26, 2020
    risk 0.66cvss 9.8epss 0.33

    Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.

  • CVE-2019-16340CriNov 21, 2019
    risk 0.65cvss 9.8epss 0.19

    Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.

  • CVE-2010-1573CriJun 10, 2010
    risk 0.65cvss 9.8epss 0.21

    Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the (1) data1, (2) data2, or (3) data3 parameters to (a)…

  • CVE-2026-27849CriFeb 25, 2026
    risk 0.64cvss 9.8epss 0.00

    Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP connection, which is normally used for configuring devices inside the mesh network. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

  • CVE-2025-29229CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.

  • CVE-2025-29228CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.

  • CVE-2025-44654CriJul 21, 2025
    risk 0.64cvss 9.8epss 0.01

    In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

  • CVE-2025-45491CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.

  • CVE-2025-45490CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.

  • CVE-2025-45489CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.

  • CVE-2025-45488CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.11

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.

  • CVE-2025-45487CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.11

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.

  • CVE-2024-57225CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.

  • CVE-2024-57224CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.

  • CVE-2024-57223CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

  • CVE-2023-46012CriMay 7, 2024
    risk 0.64cvss 9.8epss 0.02

    Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP request to the IGD UPnP.

  • CVE-2024-33789CriMay 3, 2024
    risk 0.64cvss 9.8epss 0.02

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.