Linksys FGW3000 Command Injection Vulnerability in HTTP POST Request Handler

Vulnerability

A critical command injection vulnerability has been identified in Linksys FGW3000-AH and FGW3000-HK routers running versions prior to 1.0.17.000000. The issue arises in the HTTP POST Request Handler, specifically within the 'control_panel_sw' function of the '/cgi-bin/sysconf.cgi' file. The vulnerability allows remote attackers to inject commands by manipulating the 'filename' argument.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device.

Reproduction

To reproduce this vulnerability, send an HTTP POST request to the '/cgi-bin/sysconf.cgi' endpoint, including a crafted 'filename' argument that contains the injected command. The device will execute the injected command with its system privileges.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.