Command Injection Vulnerability in Linksys FGW3000-AH and FGW3000-HK
CVE-2025-5000
5.3MEDIUM
What is CVE-2025-5000?
A command injection vulnerability exists in Linksys FGW3000-AH and FGW3000-HK routers due to improper handling of input in the HTTP POST request for the control_panel_sw in the /cgi-bin/sysconf.cgi file. An attacker can manipulate the argument 'filename', which may allow for arbitrary command execution. This flaw allows for remote exploitation of the device without authentication, potentially compromising network security. Despite prior notification to the vendor, no response was received, raising concerns about potential risks to users.
Affected Version(s)
FGW3000-AH 1.0.0
FGW3000-AH 1.0.1
FGW3000-AH 1.0.2