Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in the apply.cgi ping_ip parameter on TCP port 52000.
https://thehackernews.com/2025/01/hackers-exploit-zero-day-in-cnpilot.html
https://thehackernews.com/2025/01/mirai-botnet-variant-exploits-four.html
https://securityaffairs.com/172805/malware/gayfemboy-mirai-botnet-four-faith-flaw.html
https://blog.xlab.qianxin.com/gayfemboy/
https://blog.xlab.qianxin.com/catddos-derivative-en/
https://www.exploit-db.com/exploits/26415
https://web.archive.org/web/20140421001918/https://www.trustwave.com/spiderlabs/advisories/TWSL2013-008.txt
Source: Mitre, NVD
Published: 2025-07-11
Updated: 2025-07-15
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 8.3
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
EPSS: 0.05368