PT-2025-1324 · Undefined · Undefined
CVE-2013-3307
·
Published
2025-01-07
·
Updated
2026-07-29
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Linksys E1000 versions prior to 2.1.03
Linksys E1200 versions prior to 2.0.05
Linksys E3200 versions prior to 1.0.05
Description
OS command injection is possible via shell metacharacters in the
ping ip parameter of the 'apply.cgi' endpoint on TCP port 52000. OS command injection is a flaw that allows an attacker to execute arbitrary operating system commands on the target machine.Recommendations
Update Linksys E1000 to version 2.1.03 or later.
Update Linksys E1200 to version 2.0.05 or later.
Update Linksys E3200 to version 1.0.05 or later.
As a temporary workaround, restrict access to the 'apply.cgi' endpoint on TCP port 52000 or avoid using the
ping ip parameter.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined