Linksys FGW3000 Command Injection Vulnerability in HTTP POST Request Handler
Vulnerability
A critical command injection vulnerability has been identified in the Linksys FGW3000-AH and FGW3000-HK models, all versions prior to 1.0.17.000000. The issue arises in the HTTP POST request handler, specifically within the '/cgi-bin/sysconf.cgi' file and the 'sub_4153FC' function. The vulnerability is triggered by manipulating the 'supplicant_rnd_id_en' argument, allowing remote exploitation.
Impact
Exploitation of this vulnerability allows for arbitrary command execution on the affected device.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
7.5exploitability
5.2remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
0.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
