Executive brief
A security vulnerability has been identified in the Linksys E1200 v2 router, a device used to provide wireless internet connectivity for homes and small offices. An attacker within range of the wireless network or on the local network can send specially crafted requests to the router to take control of the device. This could allow an unauthorized user to intercept network traffic, disrupt internet service, or use the router as a foothold to attack other devices on the network.
Technical details
An unauthenticated command injection vulnerability exists in the 'httpd' binary of Linksys E1200 v2 routers running firmware version E1200_v2.0.11.001_us.tar.gz. The flaw is located within the 'Start_EPI' function, which retrieves several CGI parameters (wl_ant, wl_ssid, wl_rate, ttcp_num, ttcp_ip, and ttcp_size) via 'get_cgi'. These parameters are concatenated into system command strings using 'sprintf' without adequate sanitization of shell metacharacters. The resulting strings are subsequently executed via 'wl_exec_cmd' or 'mysystem'. A remote attacker on the adjacent network can exploit this by sending a POST request to '/cgi-bin/Start_EPI' containing malicious shell commands, leading to arbitrary code execution with the privileges of the web server.
Affected products
- Linksys E1200 v2 Router E1200_v2.0.11.001_us.tar.gz
Timeline
- 2025-11-13: advisory: Initial disclosure of CVE-2025-60689