Threats Tagged 'cve-2025-34037'
View all threats tagged with 'cve-2025-34037'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-34037'
Click on any threat for detailed analysis and mitigation recommendations
An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The vulnerability arises because the CGI scripts improperly process user input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This flaw is actively exploited in the wild by the "TheMoon" worm to deploy a MIPS ELF payload, enabling arbitrary code execution on affected routers. Other Linksys products, including WAG, WAP, WES, WET, WRT-series routers and Wireless-N access points, may also be affected. No patch or remediation information is currently available. Join the discussion | GCVE Database | 06/26/2025, 21:31:03 UTC Added: 07/22/2026, 23:24:25 UTC |
0 An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability was reported to be exploited in the wild by the "TheMoon" worm in 2014 to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. Additionally, this vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC. Join the discussion | CVE Database V5 | 06/24/2025, 01:03:27 UTC Added: 06/24/2025, 01:09:39 UTC |
Showing 1 to 2 of 2 results