VYPR

Vendor CVEs

Linksys

All CVEs

246 total · sorted by risk
  • CVE-2025-34037CriJun 24, 2025
    risk 0.75cvss epss 0.86

    An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization,…

  • CVE-2017-17411CriDec 21, 2017
    risk 0.74cvss 9.8epss 0.88

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper…

  • CVE-2013-2681CriFeb 5, 2020
    risk 0.68cvss 9.8epss 0.10

    Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.

  • CVE-2020-35713CriDec 26, 2020
    risk 0.66cvss 9.8epss 0.33

    Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.

  • CVE-2019-16340CriNov 21, 2019
    risk 0.65cvss 9.8epss 0.19

    Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.

  • CVE-2010-1573CriJun 10, 2010
    risk 0.65cvss 9.8epss 0.21

    Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the (1) data1, (2) data2, or (3) data3 parameters to (a)…

  • CVE-2026-27849CriFeb 25, 2026
    risk 0.64cvss 9.8epss 0.00

    Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP connection, which is normally used for configuring devices inside the mesh network. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

  • CVE-2025-29229CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.

  • CVE-2025-29228CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.

  • CVE-2025-44654CriJul 21, 2025
    risk 0.64cvss 9.8epss 0.01

    In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

  • CVE-2025-45491CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.

  • CVE-2025-45490CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.

  • CVE-2025-45489CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.

  • CVE-2025-45488CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.11

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.

  • CVE-2025-45487CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.11

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.

  • CVE-2024-57225CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.

  • CVE-2024-57224CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.

  • CVE-2024-57223CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

  • CVE-2023-46012CriMay 7, 2024
    risk 0.64cvss 9.8epss 0.02

    Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP request to the IGD UPnP.

  • CVE-2024-33789CriMay 3, 2024
    risk 0.64cvss 9.8epss 0.02

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.

  • CVE-2022-38555CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.09

    Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.

  • CVE-2013-4658CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.09

    Linksys EA6500 has SMB Symlink Traversal allowing symbolic links to be created to locations outside of the Samba share.

  • CVE-2019-11535CriJul 17, 2019
    risk 0.64cvss 9.8epss 0.05

    Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execution. An attacker can access system OS configurations and commands that are not intended for use beyond the web UI.

  • CVE-2025-60690HigNov 13, 2025
    risk 0.61cvss 8.8epss 0.04

    A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to four user-supplied CGI parameters matching _0~3 into a fixed-size buffer (a2)…

  • CVE-2013-3307HigJul 11, 2025
    risk 0.61cvss 8.3epss 0.53

    Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in the apply.cgi ping_ip parameter on TCP port 52000.

  • CVE-2022-38841HigApr 16, 2023
    risk 0.61cvss 8.8epss 0.11

    Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page.

  • CVE-2013-10058HigAug 1, 2025
    risk 0.59cvss epss 0.03

    An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) running firmware version v2.0.03 via the apply.cgi endpoint. The web interface fails to properly sanitize user-supplied input passed to the ping_size parameter…

  • CVE-2024-25852HigApr 11, 2024
    risk 0.59cvss 8.8epss 0.17

    Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.

  • CVE-2024-27497HigMar 1, 2024
    risk 0.59cvss 8.8epss 0.27

    Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.

  • CVE-2026-4558HigMar 22, 2026
    risk 0.58cvss 8.8epss 0.05

    A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipulation of the argument configApSsid/configApPassphrase/srpLogin/srpPassword can lead to os command injection. The attack may be…

  • CVE-2025-52692HigDec 19, 2025
    risk 0.58cvss 8.8epss 0.06

    Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially crafted URL to access certain administration functions without login credentials.

  • CVE-2025-9482HigAug 26, 2025
    risk 0.58cvss 8.8epss 0.08

    A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This impacts the function portRangeForwardAdd of the file /goform/portRangeForwardAdd. The manipulation of the argument…

  • CVE-2021-25310HigFeb 2, 2021
    risk 0.58cvss 8.8epss 0.05

    The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the ui_language POST parameter to the apply.cgi form endpoint. This occurs…

  • CVE-2009-5157HigJun 11, 2019
    risk 0.58cvss 8.8epss 0.06

    On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell metacharacters in the setup.cgi c4_ping_ipaddr variable.

  • CVE-2025-14136HigDec 6, 2025
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function RE2000v2Repeater_get_wired_clientlist_setClientsName of the file mod_form.so. The…

  • CVE-2025-14135HigDec 6, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function AP_get_wired_clientlist_setClientsName of the file mod_form.so. The manipulation of the argument…

  • CVE-2025-14134HigDec 6, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this issue is the function RE2000v2Repeater_get_wireless_clientlist_setClientsName of the file mod_form.so. Executing…

  • CVE-2025-14133HigDec 6, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this vulnerability is the function AP_get_wireless_clientlist_setClientsName of the file mod_form.so. Performing…

  • CVE-2025-60691HigNov 13, 2025
    risk 0.57cvss 8.8epss 0.01

    A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The apply_cgi and block_cgi functions copy user-supplied input from the "url" CGI parameter into stack buffers (v36, v29) using sprintf without bounds…

  • CVE-2025-9527HigAug 27, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Linksys E1700 1.0.0.4.003. This affects the function QoSSetup of the file /goform/QoSSetup. Performing manipulation of the argument ack_policy results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made…

  • CVE-2025-9526HigAug 27, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the file /goform/setSysAdm. Such manipulation of the argument rm_port leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been…

  • CVE-2025-9525HigAug 27, 2025
    risk 0.57cvss 8.8epss 0.01

    A flaw has been found in Linksys E1700 1.0.0.4.003. Affected by this vulnerability is the function setWan of the file /goform/setWan. This manipulation of the argument DeviceName/lanIp causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been…

  • CVE-2025-9483HigAug 26, 2025
    risk 0.57cvss 8.8epss 0.01

    A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected is the function singlePortForwardAdd of the file /goform/singlePortForwardAdd. This manipulation of the argument…

  • CVE-2025-9481HigAug 26, 2025
    risk 0.57cvss 8.8epss 0.01

    A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function setIpv6 of the file /goform/setIpv6. The manipulation of the argument tunrd_Prefix leads to…

  • CVE-2025-9393HigAug 24, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function addStaProfile of the file /goform/addStaProfile. Performing manipulation of the argument…

  • CVE-2025-9392HigAug 24, 2025
    risk 0.57cvss 8.8epss 0.04

    A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function qosClassifier of the file /goform/qosClassifier. Such manipulation of the argument…

  • CVE-2025-9363HigAug 23, 2025
    risk 0.57cvss 8.8epss 0.04

    A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function portTriggerManageRule of the file /goform/portTriggerManageRule. The manipulation of the argument…

  • CVE-2025-9361HigAug 23, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The affected element is the function ipRangeBlockManageRule of the file /goform/ipRangeBlockManageRule. Performing manipulation of…

  • CVE-2025-9360HigAug 23, 2025
    risk 0.57cvss 8.8epss 0.01

    A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Impacted is the function accessControlAdd of the file /goform/accessControlAdd. Such manipulation of the argument…

  • CVE-2025-9359HigAug 23, 2025
    risk 0.57cvss 8.8epss 0.01

    A weakness has been identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function RP_checkCredentialsByBBS of the file /goform/RP_checkCredentialsByBBS. This manipulation of the…

Page 1 of 5