OS Command Injection Vulnerability in Linksys ESeries Routers
CVE-2018-3954
What is CVE-2018-3954?
Linksys ESeries routers are vulnerable to an OS command injection attack that exploits improper data filtering in the router's web portal. Specifically, the vulnerability allows attackers to manipulate the 'Router Name' input field, sending malicious data to the router's configuration functions via the 'apply.cgi' interface. This can ultimately enable unauthorized access and control over the router's settings, making it imperative for users to apply the necessary updates to secure their devices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ESeries E1200 Firmware Version 2.0.09
ESeries E2500 Firmware Version 3.0.04
References
EPSS Score
7% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved