← Back

Linksys

linksys

223 CVEs • 143 products

Products (143)

Click to collapse
Toggle
Wrt54g
wrt54g
Befsr41
befsr41
Ea6500
ea6500
Wap11
wap11
Befvp41
befvp41
Wag54gs
wag54gs
Befn2ps4
befn2ps4
Befsr81
befsr81
Befsr11
befsr11
Befsru31
befsru31
Befsx41
befsx41
Befw11s4
befw11s4
Wrt54gs
wrt54gs
Wet11
wet11
Wap55ag
wap55ag
Wvc11b
wvc11b
Wrt54g V5
wrt54g_v5
Spa941
spa941
Wrt54gl
wrt54gl
Wap400n
wap400n
Ea4500
ea4500
Ea6400
ea6400
E4200v2
e4200v2
Ea6300
ea6300
Ea6900
ea6900
Ea2700
ea2700
Ea3500
ea3500
Ea6200
ea6200
Ea6700
ea6700
Hpro200
hpro200
Befcmu10
befcmu10
Befsr41w
befsr41w
Rv082
rv082
Befsr41 V3
befsr41_v3
Befw11s4 V3
befw11s4_v3
Befw11s4 V4
befw11s4_v4
Rt31p2
rt31p2
Spa921
spa921
Wag200g
wag200g
Wrt54gc
wrt54gc
Wrt300n
wrt300n
Wrt350n
wrt350n
Wap4400n
wap4400n
Wap54gv3
wap54gv3
Wrt54gx
wrt54gx
Wvbr0 Firmware
wvbr0_firmware
Velop Firmware
velop_firmware
E5350 Firmware
e5350_firmware
E1000 Firmware
e1000_firmware
E1500 Firmware
e1500_firmware
E3000 Firmware
e3000_firmware

CVEs (223)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Linksys
1E5600 Firmware
Jun 10, 2025
May 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.
1Linksys
1Re7000 Firmware
Jun 17, 2025
Apr 11, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device adminis...Show more
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.Show less
1Linksys
1E1000 Firmware
Jun 10, 2025
Mar 19, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
There is stack-based buffer overflow vulnerability in pc_change_act function in Linksys E1000 router firmware version v.2.1.03 and before, leading to remote code execution.
1Linksys
1E2000 Firmware
Jun 27, 2025
Mar 1, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.
1Linksys
1E1700 Firmware
Apr 8, 2025
Feb 27, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTime function.
1Linksys
1E1700 Firmware
Apr 8, 2025
Feb 27, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET request to the /goform/* URI or via the ExportSettings function.
1Linksys
1Wrt54gl Firmware
Nov 21, 2024
Feb 10, 2024
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
A vulnerability was found in Linksys WRT54GL 4.30.18. It has been declared as problematic. This vulnerability affects unknown code of the file /SysInfo1.htm of the component Web Management Interface. The manipulation lea...Show more
A vulnerability was found in Linksys WRT54GL 4.30.18. It has been declared as problematic. This vulnerability affects unknown code of the file /SysInfo1.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. VDB-253330 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Linksys
1Wrt54gl Firmware
Nov 21, 2024
Feb 10, 2024
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
A vulnerability was found in Linksys WRT54GL 4.30.18. It has been classified as problematic. This affects an unknown part of the file /wlaninfo.htm of the component Web Management Interface. The manipulation leads to inf...Show more
A vulnerability was found in Linksys WRT54GL 4.30.18. It has been classified as problematic. This affects an unknown part of the file /wlaninfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. The identifier VDB-253329 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Linksys
1Wrt54gl Firmware
Nov 21, 2024
Feb 9, 2024
N/A· v4
7.5 HIGH· v3
3.3 LOW· v2
A vulnerability was found in Linksys WRT54GL 4.30.18 and classified as problematic. Affected by this issue is some unknown functionality of the file /SysInfo.htm of the component Web Management Interface. The manipulatio...Show more
A vulnerability was found in Linksys WRT54GL 4.30.18 and classified as problematic. Affected by this issue is some unknown functionality of the file /SysInfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-253328. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Linksys
1E2000 Firmware
Jan 21, 2025
May 23, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ssid, wl_a...Show more
There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ssid, wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.Show less
1Linksys
1E2000 Firmware
Jan 21, 2025
May 23, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters WL_atten_bb,...Show more
There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters WL_atten_bb, WL_atten_radio, and WL_atten_ctl in the apply.cgi interface, thereby gaining shell privileges.Show less
1Linksys
1Wrt54gl Firmware
Jan 28, 2025
May 22, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ant...Show more
There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.Show less
1Linksys
1E8450 Firmware
Feb 6, 2025
Apr 16, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page.
1Linksys
1Wrt54gl Firmware
Nov 21, 2024
Jan 9, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. The Check_TSSI function within the httpd binary uses unvalidated user input in the constructi...Show more
An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. The Check_TSSI function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious POST request to /apply.cgi to execute arbitrary commands on the underlying Linux operating system as root.Show less
1Linksys
1Wrt54gl Firmware
Nov 21, 2024
Jan 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereference in the soap_action function within the upnp binary can be triggered...Show more
A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereference in the soap_action function within the upnp binary can be triggered by an unauthenticated attacker via a malicious POST request invoking the AddPortMapping action.Show less
1Linksys
1Wumc710 Firmware
Nov 21, 2024
Jan 9, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An arbitrary code exection vulnerability exists in Linksys WUMC710 Wireless-AC Universal Media Connector with firmware <= 1.0.02 (build3). The do_setNTP function within the httpd binary uses unvalidated user input in the...Show more
An arbitrary code exection vulnerability exists in Linksys WUMC710 Wireless-AC Universal Media Connector with firmware <= 1.0.02 (build3). The do_setNTP function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious GET or POST request to /setNTP.cgi to execute arbitrary commands on the underlying Linux operating system as root.Show less
1Linksys
1Wrt54gl Firmware
Nov 21, 2024
Jan 9, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
A buffer overflow vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A stack-based buffer overflow in the Start_EPI function within the httpd binary allows an authenticated...Show more
A buffer overflow vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A stack-based buffer overflow in the Start_EPI function within the httpd binary allows an authenticated attacker with administrator privileges to execute arbitrary commands on the underlying Linux operating system as root. This vulnerablity can be triggered over the network via a malicious POST request to /apply.cgi.Show less
1Linksys
1E5350 Firmware
Nov 21, 2024
Sep 12, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
On Linksys E5350 WiFi Router with firmware version 1.0.00.037 and lower, (and potentially other vendors/devices due to code reuse), the /SysInfo.htm URI does not require a session ID. This web page calls a show_sysinfo f...Show more
On Linksys E5350 WiFi Router with firmware version 1.0.00.037 and lower, (and potentially other vendors/devices due to code reuse), the /SysInfo.htm URI does not require a session ID. This web page calls a show_sysinfo function which retrieves WPA passwords, SSIDs, MAC Addresses, serial numbers, WPS Pins, and hardware/firmware versions, and prints this information into the web page. This web page is visible when remote management is enabled. A user who has access to the web interface of the device can extract these secrets. If the device has remote management enabled and is connected directly to the internet, this vulnerability is exploitable over the internet without interaction.Show less
1Linksys
1E1200 Firmware
Nov 21, 2024
Aug 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
1Linksys
1Mr8300 Firmware
Nov 21, 2024
Aug 24, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Command injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By specifying username and password, an attacker connected to the router's web interface can execute arbitrary OS commands. The...Show more
Command injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By specifying username and password, an attacker connected to the router's web interface can execute arbitrary OS commands. The username and password fields are not sanitized correctly and are used as URL construction arguments, allowing URL redirection to an arbitrary server, downloading an arbitrary script file, and eventually executing the file in the device. This issue affects: Linksys MR8300 Router 1.0.Show less