← Vulnerability feed

Vulnerability record · CVE-2024-22544 · published 27 February 2024

CVE-2024-22544: Linksys e1700 firmware command injection vulnerability

Linksys · E1700 Firmware

An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTime function.

8.0 CVSS 3.1 High EPSS 9.3% · top 4.8% CWE-77 · Command injection
8.0CVSS 3.1 base score
9.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTime function.

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-22544 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.4CVE-2025-9527Linksys e1700 firmware memory buffer overflow vulnerabilityA vulnerability was found in Linksys E1700 1.0.0.4.003. This affects the function QoSSetup of the file /goform/QoSSetup. Performing manipulation of t…EPSS 1.5%7.4CVE-2025-9525Linksys e1700 firmware memory buffer overflow vulnerabilityA flaw has been found in Linksys E1700 1.0.0.4.003. Affected by this vulnerability is the function setWan of the file /goform/setWan. This manipulati…EPSS 1.4%7.4CVE-2025-9526Linksys e1700 firmware memory buffer overflow vulnerabilityA vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the file /goform/setSysAdm. Such man…EPSS 1.4%6.1CVE-2024-22543Linksys e1700 firmware insufficient session expiration vulnerabilityAn issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET request to …EPSS 1.2%2.0CVE-2025-9528Linksys E1700 systemCommand OS command injectionThe Linksys E1700 firmware 1.0.0.4.003 exposes the /goform/systemCommand endpoint, where the systemCommand function passes a user-supplied command ar…EPSS 54%analysed9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2024-22544), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.