Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.
https://blog.xlab.qianxin.com/catddos-derivative-en/
https://github.com/ZackSecurity/VulnerReport/blob/cve/Linksys/1.md