Linksys E8450 Command Injection Vulnerability in Email Registration

Vulnerability

A command injection vulnerability has been identified in the Linksys E8450 router, specifically in firmware version 1.2.00.360516. The issue arises in the JSON parsing function of the device's portal CGI script, where the 'userEmail' field can be manipulated to execute arbitrary commands on the system.

Impact

Exploitation of this vulnerability allows for unauthenticated command injection, where an attacker can execute arbitrary commands on the router's operating system.

Reproduction

To reproduce this vulnerability, send a JSON payload to the '/cgi-bin/portal.cgi' endpoint. The payload should include an 'action' field set to 'register_email', a 'page' field set to 'register_email_wizard', and a 'userEmail' field containing the crafted command injection payload. The 'id_email_check_btn' field can be left empty.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
9.1
remediation
0.0
relevance
0.0
threat
6.5
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.