CVE-2013-2678

High PUBLISHED

Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive...

Cisco · Linksys E4200

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
8.1 High

At a Glance

Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the submit_type parameter.

CVE Published
Feb 04, 2020
Exploitation Reported
Nov 23, 2025
CVSS
8.1 High
EPSS
Remote No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • 25292 exploit-db.com · Exploit http://www.exploit-db.com/exploits/25292
  • 59710 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/59710
  • 84027 exchange.xforce.ibmcloud.com · VDB Entry https://exchange.xforce.ibmcloud.com/vulnerabilities/84072
  • packetstormsecurity.com/files/121551/Cisco-Linksys-E4200-Cross-Site-... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/121551/Cisco-Linksys-E4200-Cross...

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.