Command Injection Vulnerability in Linksys FGW3000-AH and FGW3000-HK
CVE-2025-5000
What is CVE-2025-5000?
A command injection vulnerability exists in Linksys FGW3000-AH and FGW3000-HK routers due to improper handling of input in the HTTP POST request for the control_panel_sw in the /cgi-bin/sysconf.cgi file. An attacker can manipulate the argument 'filename', which may allow for arbitrary command execution. This flaw allows for remote exploitation of the device without authentication, potentially compromising network security. Despite prior notification to the vendor, no response was received, raising concerns about potential risks to users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FGW3000-AH 1.0.0
FGW3000-AH 1.0.1
FGW3000-AH 1.0.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved