CVE-2025-34037
An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability was reported to be exploited in the wild by the "TheMoon" worm in 2014 to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. Additionally, this vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 93%
- Percentil entre todas las CVEs puntuadas: 100
- Fecha de la puntuación: 29/9/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access95 % - Impacto principal
T1059Command and Scripting Interpreterexecution95 % - Impacto secundario
T1068Exploitation for Privilege Escalationprivilege escalation75 %
AV:N/PR:N/UI:N confirma acceso remoto sin privilegios ni interacción. CWE-78 es inyección de comandos OS. El texto documenta ejecución arbitraria de código en el router mediante parámetro ttcp_ip sin sanitizar.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (6)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-78
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-34037",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-34037",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-06-24T15:53:22.492810Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 10,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "disclosure@vulncheck.com",
"affectedData": [
{
"vendor": "Linksys",
"modules": [
"Web Management Interface (tmUnblock.cgi and hndUnblock.cgi CGI scripts)"
],
"product": "E4200",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.0.06",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Linksys",
"product": "E3200",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.0.05",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Linksys",
"product": "E3000",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.0.06",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Linksys",
"product": "E2500 v1/v2",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.0.00",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Linksys",
"product": "E2100L v1",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "1.0.05"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Linksys",
"product": "E2000",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Linksys",
"product": "E1550",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "1.0.03"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Linksys",
"product": "E1500 v1",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.0.06",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Linksys",
"product": "E1200 v1",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "1.0.04"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Linksys",
"product": "E1000 v1",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.1.03",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Linksys",
"product": "E900 v1",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.0.04",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-06-24T01:15:25.037",
"references": [
{
"url": "https://isc.sans.edu/diary/17633",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://vulncheck.com/advisories/linksys-routers-command-injection",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://www.exploit-db.com/exploits/31683",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://github.com/Jarrettgohxz/CVE-research/tree/main/Linksys/E-series/CVE-2025-34037",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability was reported to be exploited in the wild by the \"TheMoon\" worm in 2014 to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. Additionally, this vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de inyección de comandos del sistema operativo en varios modelos de routers E-Series Linksys a través de los endpoints /tmUnblock.cgi y /hndUnblock.cgi a través de HTTP en el puerto 8080. Los scripts CGI procesan incorrectamente la entrada proporcionada por el usuario al parámetro ttcp_ip sin sanitizarla, lo que permite a atacantes no autenticados inyectar comandos de shell. Esta vulnerabilidad es explotada por el gusano \"TheMoon\" para desplegar un payload MIPS ELF, lo que permite la ejecución de código arbitrario en el router. Esta vulnerabilidad puede afectar a otros productos Linksys, incluyendo, entre otros, los modelos de routers de las series WAG/WAP/WES/WET/WRT y los puntos de acceso y routers Wireless-N."
}
],
"lastModified": "2026-07-22T16:17:05.520",
"sourceIdentifier": "disclosure@vulncheck.com"
}