← Back

Linksys

linksys

223 CVEs • 143 products

Products (143)

Click to collapse
Toggle
Wrt54g
wrt54g
Befsr41
befsr41
Ea6500
ea6500
Wap11
wap11
Befvp41
befvp41
Wag54gs
wag54gs
Befn2ps4
befn2ps4
Befsr81
befsr81
Befsr11
befsr11
Befsru31
befsru31
Befsx41
befsx41
Befw11s4
befw11s4
Wrt54gs
wrt54gs
Wet11
wet11
Wap55ag
wap55ag
Wvc11b
wvc11b
Wrt54g V5
wrt54g_v5
Spa941
spa941
Wrt54gl
wrt54gl
Wap400n
wap400n
Ea4500
ea4500
Ea6400
ea6400
E4200v2
e4200v2
Ea6300
ea6300
Ea6900
ea6900
Ea2700
ea2700
Ea3500
ea3500
Ea6200
ea6200
Ea6700
ea6700
Hpro200
hpro200
Befcmu10
befcmu10
Befsr41w
befsr41w
Rv082
rv082
Befsr41 V3
befsr41_v3
Befw11s4 V3
befw11s4_v3
Befw11s4 V4
befw11s4_v4
Rt31p2
rt31p2
Spa921
spa921
Wag200g
wag200g
Wrt54gc
wrt54gc
Wrt300n
wrt300n
Wrt350n
wrt350n
Wap4400n
wap4400n
Wap54gv3
wap54gv3
Wrt54gx
wrt54gx
Wvbr0 Firmware
wvbr0_firmware
Velop Firmware
velop_firmware
E5350 Firmware
e5350_firmware
E1000 Firmware
e1000_firmware
E1500 Firmware
e1500_firmware
E3000 Firmware
e3000_firmware

CVEs (223)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Linksys
1E8450 Firmware
Apr 22, 2025
Jan 21, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status.
1Linksys
1E5600 Firmware
Jun 11, 2025
Jan 15, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the...Show more
A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter.Show less
1Linksys
1E5600 Firmware
Jun 11, 2025
Jan 15, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the...Show more
A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter.Show less
1Linksys
1E7350 Firmware
Apr 16, 2025
Jan 10, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.
1Linksys
1E7350 Firmware
Apr 16, 2025
Jan 10, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.
1Linksys
1E7350 Firmware
Apr 16, 2025
Jan 10, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function.
1Linksys
1E7350 Firmware
Apr 16, 2025
Jan 10, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.
1Linksys
1E7350 Firmware
Apr 16, 2025
Jan 10, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.
1Linksys
1E7350 Firmware
Apr 16, 2025
Jan 10, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.
1Linksys
1E7350 Firmware
Apr 16, 2025
Jan 10, 2025
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.
1Linksys
1E3000 Firmware
Jun 30, 2025
Nov 21, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function.
1Linksys
1Wrt54g Firmware
Sep 5, 2024
Sep 4, 2024
5.3 MEDIUM· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the function validate_services_port of the file /apply.cgi of the component POST Parameter Handler. The manipul...Show more
A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the function validate_services_port of the file /apply.cgi of the component POST Parameter Handler. The manipulation of the argument services_array leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Linksys
1E1500 Firmware
Aug 20, 2024
Aug 19, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authenticated attacker can execute OS commands with root privileges.
1Linksys
1E2500 Firmware
Jan 2, 2026
Jul 24, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute arbitrary code via the hnd_parentalctrl_unblock function.
1Linksys
1Wrt54g Firmware
Jun 4, 2025
Jul 19, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Linksys WRT54G v4.21.5 has a stack overflow vulnerability in get_merge_mac function.
1Linksys
2Mbe7000 Firmware
Mx6200 Firmware
Jun 30, 2025
Jul 9, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during app-based installation.
1Linksys
1Velop Whw0101 Firmware
Nov 21, 2024
Jun 11, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root.
1Linksys
1E5600 Firmware
Jun 10, 2025
May 28, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue discovered in Linksys E5600 routers allows attackers to hijack TCP sessions which could lead to a denial of service.
1Linksys
1Ea7500 Firmware
Jun 30, 2025
May 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP request to the IGD UPnP.
1Linksys
1E5600 Firmware
Jun 11, 2025
May 6, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.