216.73.217.22

CVE-2025-34037

· Published 24/06/2025 03:15 · Modified 20/03/2026 21:21 · Author: AlienVault

Labels: CVE-2025-34037 2025-06-24CVE-2025-34037CWE-20[email protected]

Essential information

Published
24/06/2025 03:15
Modified
20/03/2026 21:21
Author
AlienVault
Creator
AlienVault
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CWE-78
CVSS vector

CVSS metrics

Description

An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability was reported to be exploited in the wild by the "TheMoon" worm  in 2014 to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. Additionally, this vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
linksys / e-series router cpe:2.3:a:linksys:e-series_router:*:*:*:*:*:*:*:*
linksys / wrt series router cpe:2.3:a:linksys:wrt_series_router:*:*:*:*:*:*:*:*
linksys / wag series router cpe:2.3:a:linksys:wag_series_router:*:*:*:*:*:*:*:*
linksys / wap series router cpe:2.3:a:linksys:wap_series_router:*:*:*:*:*:*:*:*
linksys / wes series router cpe:2.3:a:linksys:wes_series_router:*:*:*:*:*:*:*:*
linksys / wet series router cpe:2.3:a:linksys:wet_series_router:*:*:*:*:*:*:*:*
linksys / wifi n access point cpe:2.3:a:linksys:wifi_n_access_point:*:*:*:*:*:*:*:*

References