Junglewise Threat Intelligence

CVE-2026-86299: Linksys RE7000 OS command injection in PingTest handler

CVE-2026-86299 · Severity: critical · CVSS 9.9 · Published 2026-09-07

Technologies: Linksys Re7000. Vendors: Linksys.

Executive brief

The Linksys RE7000 WiFi range extender contains a remote command injection vulnerability in its web administration interface. An attacker can exploit this flaw to execute arbitrary system commands on the device without authentication, leading to complete device compromise, credential theft, or use as a pivot point into the network.

Technical details

The vulnerability is an OS command injection flaw in the PingTest handler of Linksys RE7000 firmware version 2.0.15, accessible via the /cgi-bin/json.cgi?PingTest endpoint. The function platform_event_pingTest fails to properly sanitize user-supplied parameters (pingTestIp, pingTestPktSize, pingTestTimes) before passing them to system command execution. An unauthenticated remote attacker can inject arbitrary OS commands through these parameters to achieve remote code execution with device privileges. The exploit is publicly available, increasing the risk of active exploitation.

Affected products

  • Linksys RE7000 2.0.15

Timeline

  • 2026-09-07: disclosed: Vulnerability disclosed and exploit published
  • 2026-09-07: other: Exploit confirmed public and may be used in the wild

References

Related threats