CVE-2025-34037

High PUBLISHED

Linksys Routers E/WAG/WAP/WES/WET/WRT-Series

Linksys · E4200, E3200, E3000, E2500 v1/v2, E2100L v1, E2000, E1550, E1500 v1, E1200 v1, E1000 v1, E900 v1

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
10.0 Critical EPSS 85.4%

At a Glance

An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability was reported to be exploited in the wild by the "TheMoon" worm  in 2014 to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. Additionally, this vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.

edge
CVE Published
Jun 24, 2025
Exploitation Reported
Jun 01, 2026
CVSS
10.0 Critical
EPSS
85.4%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Linksys
E4200

0 to < 1.0.06

Affected
Linksys
E3200

0 to < 1.0.05

Affected
Linksys
E3000

0 to < 1.0.06

Affected
Linksys
E2500 v1/v2

0 to < 2.0.00

Affected
Linksys
E2100L v1

0 to <= 1.0.05

Affected
Linksys
E2000

0

Affected
Linksys
E1550

0 to <= 1.0.03

Affected
Linksys
E1500 v1

0 to < 1.0.06

Affected
Linksys
E1200 v1

0 to <= 1.0.04

Affected
Linksys
E1000 v1

0 to < 2.1.03

Affected
Linksys
E900 v1

0 to < 1.0.04

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.