← Vulnerability feed

Vulnerability record · CVE-2018-3954 · published 17 October 2018

CVE-2018-3954: Linksys e1200 firmware os command injection vulnerability

Linksys · E1200 Firmware

Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data passed to and retrieved from NVRAMData entered into the 'Router Name' input field through the web portal is submitted to apply.cgi as the value to the 'machine_name' POST parameter. When the 'preinit' binary receives the SIGHUP signal it enters a code path that calls a function named 'set_host_domain_name' from its libshared.so shared object.

7.2 CVSS 3.1 High EPSS 3.4% · top 11.7% CWE-78 · OS command injection
7.2CVSS 3.1 base score, v2 9.0
3.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data passed to and retrieved from NVRAMData entered into the 'Router Name' input field through the web portal is submitted to apply.cgi as the value to the 'machine_name' POST parameter. When the 'preinit' binary receives the SIGHUP signal it enters a code path that calls a function named 'set_host_domain_name' from its libshared.so shared object.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-3954 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-44654Linksys e2500 firmware improper access control vulnerabilityIn Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to syst…EPSS 1.0%9.8CVE-2022-38555Linksys e1200 firmware out-of-bounds write vulnerabilityLinksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.EPSS 9.8%8.8CVE-2025-60691Linksys e1200 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The apply_cgi and block_…EPSS 0.71%8.8CVE-2025-60690Linksys e1200 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.…EPSS 3.9%8.4CVE-2025-60692Linksys e1200 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.g…EPSS 0.23%8.0CVE-2024-40495Linksys e2500 firmware code injection vulnerabilityA vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute arbitrary code via the hnd_par…EPSS 0.76%7.5CVE-2025-60694Linksys e1200 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow exists in the validate_static_route function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.00…EPSS 1.1%7.2CVE-2018-3953Linksys e1200 firmware os command injection vulnerabilityDevices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to O…EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2018-3954), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.