An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability is exploited in the wild by the "TheMoon" worm to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. This vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Jun 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 24 Jun 2025 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 24 Jun 2025 03:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Linksys E-Series Routers Command Injection | Linksys Routers E/WAG/WAP/WES/WET/WRT-Series |
References |
|
Tue, 24 Jun 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability is exploited in the wild by the "TheMoon" worm to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. This vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. | |
Title | Linksys E-Series Routers Command Injection | |
Weaknesses | CWE-20 CWE-78 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-06-24T01:03:27.693Z
Updated: 2025-06-24T15:54:33.863Z
Reserved: 2025-04-15T19:15:22.546Z
Link: CVE-2025-34037

Updated: 2025-06-24T15:54:26.304Z

Status : Awaiting Analysis
Published: 2025-06-24T01:15:25.037
Modified: 2025-06-26T18:58:14.280
Link: CVE-2025-34037

No data.