OS Command Injection Vulnerability in Linksys Routers
CVE-2013-3307

8.3HIGH

Key Information:

Vendor

Linksys

Vendor
CVE Published:
11 July 2025

What is CVE-2013-3307?

CVE-2013-3307 is a notable vulnerability found in certain models of Linksys network routers, specifically targeting the E1000, E1200, and E3200 series. This vulnerability arises from an OS command injection flaw that can be exploited through the apply.cgi interface, specifically via the ping_ip parameter. The affected router models run specific firmware versions that do not adequately validate user input, allowing an attacker to manipulate command execution on the operating system level. If exploited, this vulnerability could enable cybercriminals to execute arbitrary commands on the router, potentially leading to unauthorized access to the device and the network it connects to. Such exploitation can compromise network security, resulting in data breaches, unauthorized surveillance, or the installation of additional malware within the network infrastructure of an organization.

Potential impact of CVE-2013-3307

  1. Unauthorized System Access: The vulnerability allows attackers to gain unauthorized control over affected routers, which could lead to complete management access. This access could be exploited to change network configurations, monitor traffic, intercept sensitive data, or manipulate connected devices.

  2. Network Compromise and Data Breaches: With control over the router, attackers could pivot to other devices connected to the network, compromising endpoints and potentially exfiltrating sensitive information. This could lead to a wider breach across organizational data assets.

  3. Malware Deployment: Attackers can use the OS command injection to install malicious software on the router or within the network. This could result in persistent backdoors, facilitating further attacks including ransomware deployment or the establishment of botnets for larger malicious operations.

Affected Version(s)

E1000 0 <= 2.1.02

E1200 0 < 2.0.05

E3200 0 <= 1.0.04

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.