PT-2025-1324 · Undefined · Undefined

Published

2025-01-07

·

Updated

2025-09-16

·

CVE-2013-3307

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Linksys E1000 versions through 2.1.02 Linksys E1200 versions prior to 2.0.05 Linksys E3200 versions through 1.0.04
Description: Linksys E1000, E1200, and E3200 devices are susceptible to OS command injection. The ping ip parameter within the apply.cgi script, accessible via TCP port 52000, allows injection of shell metacharacters.
Recommendations: Linksys E1000 versions through 2.1.02: Update to a later version than 2.1.02. Linksys E1200 versions prior to 2.0.05: Update to version 2.0.05 or later. Linksys E3200 versions through 1.0.04: Update to a later version than 1.0.04.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2013-3307

Affected Products

Undefined