Description
A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injection. The attack can be launched remotely. The exploit is now public and may be used.
Published: 2026-09-07
Score: 9.4 Critical
EPSS: 3.7% Low
KEV: No
Impact: Remote Command Execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability arises from improper validation of the pingTestIp, pingTestPktSize, and pingTestTimes parameters in the platform_event_pingTest function of /cgi-bin/json.cgi on the Linksys RE7000. An attacker can supply crafted input that causes the router to execute arbitrary operating system commands, resulting in administrative takeover or arbitrary code execution. The flaw corresponds to CWE-77 (Path Manipulation) and CWE-78 (OS Command Injection).

Affected Systems

Linksys RE7000 routers running firmware version 2.0.15 are impacted. No other versions or products were listed in the advisory; the issue is specific to the 2.0.15 build of the RE7000.

Risk and Exploitability

The CVSS score of 9.4 indicates critical severity. The EPSS score is 4%, indicating that while exploitation probability is relatively low overall, the vulnerability is publicly exposed and exploits are already in the wild, so the likelihood of successful exploitation remains high for exposed devices. The vulnerability is not yet listed in CISA's KEV catalog, yet it poses a significant remote attack surface for devices reachable from the internet.

Generated by OpenCVE AI on September 25, 2026 at 00:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router to a firmware version that contains the patch for the command injection flaw.
  • If a firmware update is not yet available, disable the PingTest functionality or restrict access to /cgi-bin/json.cgi through router settings.
  • Configure the network firewall or ACLs to block external traffic to /cgi-bin/json.cgi and related PingTest URLs.

Generated by OpenCVE AI on September 25, 2026 at 00:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Linksys re7000
Vendors & Products Linksys re7000

Mon, 07 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injection. The attack can be launched remotely. The exploit is now public and may be used.
Title Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection
First Time appeared Linksys
Linksys re7000 Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:linksys:re7000_firmware:*:*:*:*:*:*:*:*
Vendors & Products Linksys
Linksys re7000 Firmware
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Linksys Re7000 Re7000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-11T20:35:08.748Z

Reserved: 2026-09-06T16:32:18.951Z

Link: CVE-2026-86299

cve-icon Vulnrichment

Updated: 2026-09-11T20:15:45.098Z

cve-icon NVD

Status : Deferred

Published: 2026-09-07T12:17:21.340

Modified: 2026-09-11T21:17:44.440

Link: CVE-2026-86299

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T00:45:17Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')