Linksys E1500 Directory Traversal Vulnerability

Vulnerability

A directory traversal vulnerability has been identified in the Linksys E1500 router's web interface, specifically in the /apply.cgi endpoint. This vulnerability affects firmware versions 1.0.00, 1.0.04, and 1.0.05. Authenticated attackers can exploit the next_page POST parameter to access arbitrary files outside the intended web root by injecting traversal sequences, potentially exposing sensitive system files and configuration data.

Impact

Exploitation of this vulnerability allows authenticated attackers to access arbitrary files on the router, including sensitive system and configuration files.

Reproduction

To reproduce this vulnerability, an authenticated user can send a POST request to the /apply.cgi endpoint with the next_page parameter set to a traversal sequence that includes the desired file path. The injection of traversal sequences can bypass the web root restrictions and access files outside the intended directory.

Added: Aug 1, 2025, 9:18 PM
Updated: Aug 1, 2025, 9:18 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
5.8
remediation
0.0
relevance
0.3
threat
7.3
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.