PT-2025-22309 · Linksys · Linksys Fgw3000-Ah+1

Ch13Hh

·

Published

2025-04-26

·

Updated

2025-06-12

·

CVE-2025-4999

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linksys FGW3000-AH and FGW3000-HK versions up to 1.0.17.000000
Description A critical issue was found, affecting the function sub 4153FC of the file /cgi-bin/sysconf.cgi in the HTTP POST Request Handler component. The manipulation of the argument supplicant rnd id en leads to command injection. This issue can be exploited remotely.
Recommendations For versions up to 1.0.17.000000, as a temporary workaround, consider disabling the sub 4153FC function until a patch is available. Restrict access to the /cgi-bin/sysconf.cgi file to minimize the risk of exploitation. Avoid using the argument supplicant rnd id en in the affected HTTP POST Request Handler until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-06202
CVE-2025-4999

Affected Products

Linksys Fgw3000-Ah
Linksys Fgw3000-Hk