Linksys E7350 Command Injection Vulnerability in Vif_Disable Function

Vulnerability

A command injection vulnerability has been identified in the Linksys E7350 router, specifically in firmware version 1.1.00.032. The issue arises in the '/usr/lib/lua/luci/controller/mtkwifi.lua' file within the 'vif_disable' function, where the 'iface' parameter can be manipulated to inject and execute arbitrary commands.

Impact

Exploitation of this vulnerability allows for command injection, where an attacker can execute arbitrary commands on the device.

Reproduction

To reproduce this vulnerability, send a GET request to the '/cgi-bin/luci/admin/mtk/wifi/vif_disable/' endpoint, including the 'iface' parameter. Inject a command, such as 'ls', into the 'iface' parameter. The injected command will be executed on the device, and the results can be observed in the response.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
10.0
exploitability
6.2
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.