← Back to overview

A critical OS command injection vulnerability has been identified in the Linksys RE7000 range extender running firmware version 2.0.15. The vulnerability exists in the platform_event_pingTest function accessible via /cgi-bin/json.cgi?PingTest endpoint. Attackers can manipulate the arguments pingTestIp, pingTestPktSize, and pingTestTimes to inject arbitrary OS commands. The attack can be executed remotely without physical access to the device. A public exploit is already available, significantly increasing the risk of active exploitation. The vulnerability affects the PingTest Handler component of the device's CGI interface. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. Given the public availability of the exploit and the remote attack vector, this is considered a high-severity issue.

Affected products

  • Linksys RE7000 2.0.15

Related CVE's

  • CVE-2026-86299

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities