VYPR

Vendor CVEs

Linksys

All CVEs

247 total · sorted by risk
  • CVE-2025-9362MedAug 23, 2025
    risk 0.41cvss 6.3epss 0.01

    A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The impacted element is the function urlFilterManageRule of the file /goform/urlFilterManageRule. Executing manipulation of the argument…

  • CVE-2025-29227MedMar 21, 2025
    risk 0.41cvss 6.3epss 0.01

    In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter.

  • CVE-2025-29226MedMar 21, 2025
    risk 0.41cvss 6.3epss 0.01

    In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter.

  • CVE-2025-29223MedMar 21, 2025
    risk 0.41cvss 6.3epss 0.01

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function.

  • CVE-2024-57537MedJan 21, 2025
    risk 0.41cvss 6.3epss 0.00

    Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (page) is copied to the stack without length verification.

  • CVE-2024-57222MedJan 10, 2025
    risk 0.41cvss 6.3epss 0.01

    Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

  • CVE-2024-8408MedSep 4, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the function validate_services_port of the file /apply.cgi of the component POST Parameter Handler. The manipulation of the argument services_array leads to stack-based…

  • CVE-2026-27846MedFeb 25, 2026
    risk 0.40cvss 6.2epss 0.00

    Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a new mesh device to the network  to gain access to sensitive information, including the password for admin access to the web interface and the Wi-Fi…

  • CVE-2025-29231MedDec 16, 2025
    risk 0.40cvss 6.1epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hostname and domainName parameters.

  • CVE-2024-22543MedFeb 27, 2024
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET request to the /goform/* URI or via the ExportSettings function.

  • CVE-2013-2683MedFeb 6, 2020
    risk 0.39cvss 5.3epss 0.13

    Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresses and other sensitive information.

  • CVE-2025-60695MedNov 13, 2025
    risk 0.38cvss 5.9epss 0.00

    A stack-based buffer overflow vulnerability exists in the mtk_dut binary of Linksys E7350 routers (Firmware 1.1.00.032). The function sub_4045A8 reads up to 256 bytes from /sys/class/net/%s/address into a local buffer and then copies it into caller-provided buffer a1 using…

  • CVE-2014-125122MedJul 31, 2025
    risk 0.38cvss —epss 0.01

    A stack-based buffer overflow vulnerability exists in the tmUnblock.cgi endpoint of the Linksys WRT120N wireless router. The vulnerability is triggered by sending a specially crafted HTTP POST request with an overly long TM_Block_URL parameter to the endpoint. By exploiting this…

  • CVE-2025-60689MedNov 13, 2025
    risk 0.36cvss 5.4epss 0.17

    An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl_ant, wl_ssid, wl_rate, ttcp_num, ttcp_ip,…

  • CVE-2024-57545MedJan 21, 2025
    risk 0.36cvss 5.5epss 0.00

    Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (hidden_dhcp_num) is copied to the stack without length verification.

  • CVE-2024-57544MedJan 21, 2025
    risk 0.36cvss 5.5epss 0.00

    Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (lan_ipaddr) is copied to the stack without length verification.

  • CVE-2024-57543MedJan 21, 2025
    risk 0.36cvss 5.5epss 0.00

    Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (dhcpstart_ip) is copied to the stack without length verification.

  • CVE-2024-57541MedJan 21, 2025
    risk 0.36cvss 5.5epss 0.00

    Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (ipv6_protect_status) is copied to the stack without length verification.

  • CVE-2025-9528MedAug 27, 2025
    risk 0.35cvss 4.7epss 0.54

    A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand. Executing manipulation of the argument command can lead to os command injection. The attack may be launched remotely. The exploit…

  • CVE-2013-3067MedFeb 7, 2020
    risk 0.35cvss 5.4epss 0.01

    Linksys WRT310Nv2 2.0.0.1 is vulnerable to XSS.

  • CVE-2024-40750MedJul 9, 2024
    risk 0.34cvss 5.3epss 0.00

    Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during app-based installation.

  • CVE-2025-22997MedJan 15, 2025
    risk 0.31cvss 4.8epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter.

  • CVE-2025-22996MedJan 15, 2025
    risk 0.31cvss 4.8epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter.

  • CVE-2013-2682MedFeb 5, 2020
    risk 0.31cvss 4.3epss 0.06

    Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information.

  • CVE-2022-24372MedApr 27, 2022
    risk 0.30cvss 4.6epss 0.00

    Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of a NAS SMB share.

  • CVE-2024-1406MedFeb 10, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Linksys WRT54GL 4.30.18. It has been declared as problematic. This vulnerability affects unknown code of the file /SysInfo1.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been…

  • CVE-2024-1405MedFeb 10, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Linksys WRT54GL 4.30.18. It has been classified as problematic. This affects an unknown part of the file /wlaninfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the…

  • CVE-2024-1404MedFeb 9, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Linksys WRT54GL 4.30.18 and classified as problematic. Affected by this issue is some unknown functionality of the file /SysInfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been…

  • CVE-2025-44657LowJul 21, 2025
    risk 0.25cvss 3.9epss 0.00

    In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

  • CVE-2005-2799Sep 15, 2005
    risk 0.09cvss —epss 0.71

    Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote attackers to execute arbitrary code via a long HTTP POST request.

  • CVE-2008-6280Feb 25, 2009
    risk 0.04cvss —epss 0.07

    Cross-site scripting (XSS) vulnerability in apply.cgi on the Linksys WRT160N allows remote attackers to inject arbitrary web script or HTML via the action parameter in a DHCP_Static operation.

  • CVE-2007-2270Apr 25, 2007
    risk 0.04cvss —epss 0.09

    The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, and possibly certain other locations, in a SIP INVITE request.

  • CVE-2006-5882Nov 14, 2006
    risk 0.04cvss —epss 0.13

    Stack-based buffer overflow in the Broadcom BCMWL5.SYS wireless device driver 3.50.21.10, as used in Cisco Linksys WPC300N Wireless-N Notebook Adapter before 4.100.15.5 and other products, allows remote attackers to execute arbitrary code via an 802.11 response frame containing…

  • CVE-2004-2507Dec 31, 2004
    risk 0.04cvss —epss 0.08

    Absolute path traversal vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to read arbitrary files via an absolute pathname in the next_file parameter.

  • CVE-2004-0580Aug 6, 2004
    risk 0.04cvss —epss 0.08

    DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly clear previously used buffer contents in a BOOTP reply packet, which allows remote attackers to obtain sensitive information.

  • CVE-2002-1236Nov 12, 2002
    risk 0.04cvss —epss 0.07

    The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote attackers to cause a denial of service (crash) via an HTTP request to Gozila.cgi without any arguments.

  • CVE-2008-2092May 6, 2008
    risk 0.03cvss —epss 0.04

    Linksys SPA-2102 Phone Adapter 3.3.6 allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE: the severity of this issue has been disputed since there are limited attack scenarios.

  • CVE-2008-1247Mar 10, 2008
    risk 0.03cvss —epss 0.05

    The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts, which allows remote attackers to perform arbitrary administrative actions via a direct request to (1) Advanced.tri, (2) AdvRoute.tri, (3) Basic.tri, (4)…

  • CVE-2007-5411Oct 12, 2007
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Linksys SPA941 VoIP Phone with firmware 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the From header in a SIP message.

  • CVE-2007-3574Jul 5, 2007
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in setup.cgi on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.00.06 firmware allow remote attackers to inject arbitrary web script or HTML via the (1) c4_trap_ip_, (2) devname, (3) snmp_getcomm, or (4) snmp_setcomm…

  • CVE-2006-5202Oct 10, 2006
    risk 0.03cvss —epss 0.04

    Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using the SecurityMode and layout parameters, a different issue…

  • CVE-2005-1059May 2, 2005
    risk 0.03cvss —epss 0.03

    Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data parameter to changepw.html.

  • CVE-2004-2508Dec 31, 2004
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to inject arbitrary web script or HTML via the next_file parameter.

  • CVE-2004-0312Nov 23, 2004
    risk 0.03cvss —epss 0.06

    Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a query for OID 1.3.6.1.4.1.3955.2.1.13.1.2.

  • CVE-2002-1865Dec 31, 2002
    risk 0.03cvss —epss 0.03

    Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys Etherfast BEFW11S4 Wireless AP + Cable/DSL Router 1.37.2 through 1.42.7 and Linksys WAP11 1.3 and 1.4, allows remote attackers to cause a denial of…

  • CVE-2014-8244Nov 1, 2014
    risk 0.00cvss —epss 0.04

    Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900…

  • CVE-2014-8243Nov 1, 2014
    risk 0.00cvss —epss 0.01

    Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900…

  • CVE-2013-3068Sep 29, 2014
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in apply.cgi in Linksys WRT310Nv2 2.0.0.1 allows remote attackers to hijack the authentication of administrators for requests that change passwords and modify remote management ports.

  • CVE-2013-3066Sep 29, 2014
    risk 0.00cvss —epss 0.02

    Linksys EA6500 with firmware 1.1.28.147876 does not properly restrict access, which allows remote attackers to obtain sensitive information (clients and router configuration) via a request to /JNAP/.

  • CVE-2013-3065Sep 29, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Parental Controls section in Linksys EA6500 with firmware 1.1.28.147876 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Blocked Specific Sites section.

Page 4 of 5