Impact
The vulnerability arises from improper validation of the pingTestIp, pingTestPktSize, and pingTestTimes parameters in the platform_event_pingTest function of /cgi-bin/json.cgi on the Linksys RE7000. An attacker can supply crafted input that causes the router to execute arbitrary operating system commands, resulting in administrative takeover or arbitrary code execution. The flaw corresponds to CWE-77 (Path Manipulation) and CWE-78 (OS Command Injection).
Affected Systems
Linksys RE7000 routers running firmware version 2.0.15 are impacted. No other versions or products were listed in the advisory; the issue is specific to the 2.0.15 build of the RE7000.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. The EPSS score is 4%, indicating that while exploitation probability is relatively low overall, the vulnerability is publicly exposed and exploits are already in the wild, so the likelihood of successful exploitation remains high for exposed devices. The vulnerability is not yet listed in CISA's KEV catalog, yet it poses a significant remote attack surface for devices reachable from the internet.
OpenCVE Enrichment