← Vulnerability feed

Vulnerability record · CVE-2025-60689 · published 13 November 2025

CVE-2025-60689: Linksys e1200 firmware command injection vulnerability

Linksys · E1200 Firmware

An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl_ant, wl_ssid, wl_rate, ttcp_num, ttcp_ip, ttcp_size) are concatenated into system command strings without proper sanitization and executed via wl_exec_cmd. Successful exploitation allows remote attackers to execute arbitrary commands on the device without authentication.

5.4 CVSS 3.1 Medium EPSS 18% · top 2.9% CWE-77 · Command injection
5.4CVSS 3.1 base score
18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 1 tagged exploit
22 Jul 2026Last modified by NVD

Description

An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl_ant, wl_ssid, wl_rate, ttcp_num, ttcp_ip, ttcp_size) are concatenated into system command strings without proper sanitization and executed via wl_exec_cmd. Successful exploitation allows remote attackers to execute arbitrary commands on the device without authentication.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-60689 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-38555Linksys e1200 firmware out-of-bounds write vulnerabilityLinksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.EPSS 9.8%8.8CVE-2025-60691Linksys e1200 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The apply_cgi and block_…EPSS 0.71%8.8CVE-2025-60690Linksys e1200 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.…EPSS 3.9%8.4CVE-2025-60692Linksys e1200 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.g…EPSS 0.23%7.5CVE-2025-60694Linksys e1200 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow exists in the validate_static_route function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.00…EPSS 1.1%7.2CVE-2018-3953Linksys e1200 firmware os command injection vulnerabilityDevices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to O…EPSS 14%7.2CVE-2018-3954Linksys e1200 firmware os command injection vulnerabilityDevices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to O…EPSS 3.4%7.2CVE-2018-3955Linksys e1200 firmware os command injection vulnerabilityAn exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2…EPSS 4.8%

Source: NIST National Vulnerability Database (record CVE-2025-60689), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.