CVSS
No CVSS.
A
n authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) running firmware version v2.0.03 via the apply.cgi endpoint. The web interface fails to properly sanitize user-supplied input passed to the ping_size parameter during diagnostic operations. An attacker with valid credentials can inject arbitrary shell commands, enabling remote code execution.
References
Configurations
No configuration.
History
06 Aug 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-08-01 21:15
Updated : 2025-08-06 14:15
NVD link : CVE-2013-10058
Mitre link : CVE-2013-10058
CVE.ORG link : CVE-2013-10058
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')