Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2025-34037
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Linksys Routers E/WAG/WAP/WES/WET/WRT-Series
Source: NVD (National Vulnerability Database)
Vulnerability Description
An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability was reported to be exploited in the wild by the "TheMoon" worm  in 2014 to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. Additionally, this vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linksys E-Series 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linksys E-Series是美国Linksys公司的一款路由器。 Linksys E-Series存在安全漏洞,该漏洞源于tmUnblock.cgi和hndUnblock.cgi端点中ttcp_ip参数未清理导致OS命令注入攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
LinksysE4200 0 ~ 1.0.06 -
LinksysE3200 0 ~ 1.0.05 -
LinksysE3000 0 ~ 1.0.06 -
LinksysE2500 v1/v2 0 ~ 2.0.00 -
LinksysE2100L v1 0 ~ 1.0.05 -
LinksysE2000 0 -
LinksysE1550 0 ~ 1.0.03 -
LinksysE1500 v1 0 ~ 1.0.06 -
LinksysE1200 v1 0 ~ 1.0.04 -
LinksysE1000 v1 0 ~ 2.1.03 -
LinksysE900 v1 0 ~ 1.0.04 -
II. Public POCs for CVE-2025-34037
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2025-34037
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2025-34037

No comments yet


Leave a comment