PT-2025-26664 · Linksys · Linksys E-Series

·

CVE-2025-34037

·

Published

2025-06-23

·

Updated

2026-07-22

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Linksys E-Series routers versions prior to a firmware update Linksys E4200 Linksys E3200 Linksys E3000 Linksys E2500 Linksys E2100L Linksys E2000 Linksys E1550 Linksys E1500 Linksys E1200 Linksys E1000 Linksys E900
Description An OS command injection issue exists in Linksys E-Series routers. The vulnerability is present in the /tmUnblock.cgi and /hndUnblock.cgi API endpoints accessible via HTTP on port 8080. The scripts do not properly sanitize user-supplied input provided through the ttcp ip parameter, allowing unauthenticated attackers to inject shell commands. This issue is actively exploited in the wild by the “TheMoon” worm, which deploys a MIPS ELF payload to achieve arbitrary code execution on the router. The worm is actively exploiting this flaw to infect devices.
Recommendations For Linksys E4200 routers, segment and monitor the network. For Linksys E3200 routers, segment and monitor the network. For Linksys E3000 routers, segment and monitor the network. For Linksys E2500 routers, segment and monitor the network. For Linksys E2100L routers, segment and monitor the network. For Linksys E2000 routers, segment and monitor the network. For Linksys E1550 routers, segment and monitor the network. For Linksys E1500 routers, segment and monitor the network. For Linksys E1200 routers, segment and monitor the network. For Linksys E1000 routers, segment and monitor the network. For Linksys E900 routers, segment and monitor the network. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-11591
CVE-2025-34037

Affected Products

Linksys E-Series