{"advisories":[{"id":"EUVD-2025-18964","source":"euvd","title":"An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability is exploited in the wild by the \"TheMoon\" worm to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. This vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers.","url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-18964"}],"cve":"CVE-2025-34037","enrichment":{"created":"2026-04-28T01:30:17.914670+00:00","updated":"2026-08-14T14:45:17.270048+00:00","vendors":[]},"epss":{"score":0.90939},"mitre":{"cpes":["cpe:2.3:a:linksys:e1000:*:*:*:*:*:*:*:*","cpe:2.3:a:linksys:e1200:*:*:*:*:*:*:*:*","cpe:2.3:a:linksys:e1500:*:*:*:*:*:*:*:*","cpe:2.3:a:linksys:e2500:*:*:*:*:*:*:*:*","cpe:2.3:h:linksys:e2000:*:*:*:*:*:*:*:*","cpe:2.3:h:linksys:e3000:*:*:*:*:*:*:*:*"],"created":"2025-06-24T01:03:27.693000+00:00","description":"An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability was reported to be exploited in the wild by the \"TheMoon\" worm  in 2014 to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. Additionally, this vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":10,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}},"mitre_repo_path":"cves/2025/34xxx/CVE-2025-34037.json","references":["https://isc.sans.edu/diary/17633","https://vulncheck.com/advisories/linksys-routers-command-injection","https://www.exploit-db.com/exploits/31683"],"title":"Linksys Routers E/WAG/WAP/WES/WET/WRT-Series","updated":"2026-07-22T14:59:37.943000+00:00","vendors":["linksys","linksys$PRODUCT$e1000","linksys$PRODUCT$e1200","linksys$PRODUCT$e1500","linksys$PRODUCT$e2000","linksys$PRODUCT$e2500","linksys$PRODUCT$e3000"],"weaknesses":["CWE-78"]},"nvd":{"cpes":[],"created":"2025-06-24T01:15:25.037000+00:00","description":"An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability was reported to be exploited in the wild by the \"TheMoon\" worm  in 2014 to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. Additionally, this vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":10.0,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2025/CVE-2025-34037.json","references":["https://github.com/Jarrettgohxz/CVE-research/tree/main/Linksys/E-series/CVE-2025-34037","https://isc.sans.edu/diary/17633","https://vulncheck.com/advisories/linksys-routers-command-injection","https://www.exploit-db.com/exploits/31683"],"title":null,"updated":"2026-07-22T16:17:05.520000+00:00","vendors":[],"weaknesses":["CWE-78"]},"opencve":{"changes":[{"created":"2025-06-24T01:15:00+00:00","data":[{"details":{"new":"An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability is exploited in the wild by the \"TheMoon\" worm to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. This vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers.","old":null},"type":"description"},{"details":{"new":"Linksys E-Series Routers Command Injection","old":null},"type":"title"},{"details":{"added":["CWE-20","CWE-78"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://isc.sans.edu/diary/17633","https://vulncheck.com/advisories/linksys-multiple-routers-command-injection","https://www.exploit-db.com/exploits/31683"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV4_0":{"score":10,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"cc3b65e9-e270-4e9a-9bbe-a2d39dfc77e9"},{"created":"2025-06-24T03:15:00+00:00","data":[{"details":{"new":"Linksys Routers E/WAG/WAP/WES/WET/WRT-Series","old":"Linksys E-Series Routers Command Injection"},"type":"title"},{"details":{"added":["https://vulncheck.com/advisories/linksys-routers-command-injection"],"removed":[]},"type":"references"}],"id":"5209d1ed-00a7-424f-9432-8b0f6aca623e"},{"created":"2025-06-24T04:45:00+00:00","data":[{"details":{"added":[],"removed":["https://vulncheck.com/advisories/linksys-multiple-routers-command-injection"]},"type":"references"}],"id":"230c66a6-ec00-4c46-a70f-b7b79aa2bc35"},{"created":"2025-06-24T16:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"b27db634-032f-4681-87c2-77a05183eb6c"},{"created":"2025-07-16T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.03342},"old":{"score":0.0246}}}},"type":"metrics"}],"id":"2baff114-f721-4ca2-aeaa-15bb4b0eae06"},{"created":"2025-11-17T22:15:00+00:00","data":[{"details":{"new":"An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability is exploited in the wild by the \"TheMoon\" worm to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. This vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-07-13 UTC.","old":"An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability is exploited in the wild by the \"TheMoon\" worm to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. This vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers."},"type":"description"}],"id":"5ed2342c-54a6-41b9-a132-c302cbc00154"},{"created":"2025-11-17T22:30:00+00:00","data":[{"details":{"added":[],"removed":["CWE-20"]},"type":"weaknesses"}],"id":"23a8c29f-8e90-4649-a811-c0c55cfd55a1"},{"created":"2025-11-20T21:30:00+00:00","data":[{"details":{"new":"An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability is exploited in the wild by the \"TheMoon\" worm to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. This vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.","old":"An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability is exploited in the wild by the \"TheMoon\" worm to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. This vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-07-13 UTC."},"type":"description"}],"id":"aa051f85-842c-49d9-a5b6-f282fe91a639"},{"created":"2025-11-22T02:15:00+00:00","data":[{"details":["linksys","linksys$PRODUCT$e1000","linksys$PRODUCT$e1200","linksys$PRODUCT$e1500","linksys$PRODUCT$e2000","linksys$PRODUCT$e2500","linksys$PRODUCT$e3000"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:linksys:e1000:*:*:*:*:*:*:*:*","cpe:2.3:a:linksys:e1200:*:*:*:*:*:*:*:*","cpe:2.3:a:linksys:e1500:*:*:*:*:*:*:*:*","cpe:2.3:a:linksys:e2500:*:*:*:*:*:*:*:*","cpe:2.3:h:linksys:e2000:*:*:*:*:*:*:*:*","cpe:2.3:h:linksys:e3000:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["linksys","linksys$PRODUCT$e1000","linksys$PRODUCT$e1200","linksys$PRODUCT$e1500","linksys$PRODUCT$e2000","linksys$PRODUCT$e2500","linksys$PRODUCT$e3000"],"removed":[]},"type":"vendors"}],"id":"d88e9a80-89ac-4e43-a451-3307d27cc8dd"},{"created":"2026-03-20T18:30:00+00:00","data":[{"details":{"new":"An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability was reported to be exploited in the wild by the \"TheMoon\" worm  in 2014 to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. Additionally, this vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.","old":"An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability is exploited in the wild by the \"TheMoon\" worm to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. This vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC."},"type":"description"}],"id":"9557bb3f-6520-4c19-af63-4c92a599326f"}],"cpes":{"data":["cpe:2.3:a:linksys:e1000:*:*:*:*:*:*:*:*","cpe:2.3:a:linksys:e1200:*:*:*:*:*:*:*:*","cpe:2.3:a:linksys:e1500:*:*:*:*:*:*:*:*","cpe:2.3:a:linksys:e2500:*:*:*:*:*:*:*:*","cpe:2.3:h:linksys:e2000:*:*:*:*:*:*:*:*","cpe:2.3:h:linksys:e3000:*:*:*:*:*:*:*:*"],"providers":["mitre"]},"created":{"data":"2025-06-24T01:03:27.693000+00:00","provider":"mitre"},"description":{"data":"An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability was reported to be exploited in the wild by the \"TheMoon\" worm  in 2014 to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. Additionally, this vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{},"provider":null},"cvssV4_0":{"data":{"score":10,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"},"provider":"mitre"},"epss":{"data":{"score":0.90939},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/Jarrettgohxz/CVE-research/tree/main/Linksys/E-series/CVE-2025-34037","https://isc.sans.edu/diary/17633","https://vulncheck.com/advisories/linksys-routers-command-injection","https://www.exploit-db.com/exploits/31683"],"providers":["mitre","nvd"]},"title":{"data":"Linksys Routers E/WAG/WAP/WES/WET/WRT-Series","provider":"mitre"},"updated":{"data":"2026-04-15T00:35:42.020000+00:00","provider":"nvd"},"vendors":{"data":["linksys","linksys$PRODUCT$e1000","linksys$PRODUCT$e1200","linksys$PRODUCT$e1500","linksys$PRODUCT$e2000","linksys$PRODUCT$e2500","linksys$PRODUCT$e3000"],"providers":["mitre"]},"weaknesses":{"data":["CWE-78"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2025-06-24T01:03:27.693000+00:00","description":"An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability was reported to be exploited in the wild by the \"TheMoon\" worm  in 2014 to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. Additionally, this vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"Linksys Routers E/WAG/WAP/WES/WET/WRT-Series","updated":"2025-06-24T15:54:26.304000+00:00","vendors":[],"vulnrichment_repo_path":"2025/34xxx/CVE-2025-34037.json","weaknesses":[]}}