← Vulnerability feed

Vulnerability record · CVE-2018-3955 · published 17 October 2018

CVE-2018-3955: Linksys e1200 firmware os command injection vulnerability

Linksys · E1200 Firmware

An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04). Specially crafted entries to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send an authenticated HTTP request to trigger this vulnerability. Data entered into the 'Domain Name' input field through the web portal is submitted to apply.cgi as the value to the 'wan_domain' POST parameter. The wan_domain data goes through the nvram_set process described above. When the 'preinit' binary receives the SIGHUP signal it enters a code path that calls a function named 'set_host_domain_name' from its libshared.so shared object.

7.2 CVSS 3.1 High EPSS 4.8% · top 8.3% CWE-78 · OS command injection
7.2CVSS 3.1 base score, v2 9.0
4.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04). Specially crafted entries to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send an authenticated HTTP request to trigger this vulnerability. Data entered into the 'Domain Name' input field through the web portal is submitted to apply.cgi as the value to the 'wan_domain' POST parameter. The wan_domain data goes through the nvram_set process described above. When the 'preinit' binary receives the SIGHUP signal it enters a code path that calls a function named 'set_host_domain_name' from its libshared.so shared object.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-3955 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-44654Linksys e2500 firmware improper access control vulnerabilityIn Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to syst…EPSS 1.0%9.8CVE-2022-38555Linksys e1200 firmware out-of-bounds write vulnerabilityLinksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.EPSS 9.8%8.8CVE-2025-60691Linksys e1200 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The apply_cgi and block_…EPSS 0.71%8.8CVE-2025-60690Linksys e1200 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.…EPSS 3.9%8.4CVE-2025-60692Linksys e1200 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.g…EPSS 0.23%8.0CVE-2024-40495Linksys e2500 firmware code injection vulnerabilityA vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute arbitrary code via the hnd_par…EPSS 0.76%7.5CVE-2025-60694Linksys e1200 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow exists in the validate_static_route function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.00…EPSS 1.1%7.2CVE-2018-3953Linksys e1200 firmware os command injection vulnerabilityDevices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to O…EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2018-3955), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.