{"id":"CVE-2025-34037","title":"An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080","summary":"An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the …","severity":"none","cwe":["CWE-78"],"published":"2025-06-24","updated":"2026-07-22","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-34037","references":[{"url":"https://isc.sans.edu/diary/17633","label":"disclosure@vulncheck.com"},{"url":"https://vulncheck.com/advisories/linksys-routers-command-injection","label":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/31683","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Jarrettgohxz/CVE-research/tree/main/Linksys/E-series/CVE-2025-34037","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.90939,"epssPercentile":0.99802,"ingestedAt":"2026-07-22T17:05:16.163Z","exploits":{"github":1,"githubRepos":["https://github.com/Taxanehh/CVE-2025-34037"],"metasploit":["exploit/linux/http/linksys_themoon_exec"],"checkedAt":"2026-09-23T07:13:35.752Z"},"exploitAvailable":true,"slug":"CVE-2025-34037","body":"## Overview\n\nAn OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability was reported to be exploited in the wild by the \"TheMoon\" worm  in 2014 to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. Additionally, this vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":33,"depthScoreParts":{"impact":2.8,"likelihood":18.2,"exploitation":12,"ransomware":0},"changes":[{"seq":4812,"id":"CVE-2025-34037","ts":1788887208333,"field":"exploit_available","old":"false","new":"true"},{"seq":3695,"id":"CVE-2025-34037","ts":1788886325414,"field":"exploit_available","old":"true","new":"false"},{"seq":2540,"id":"CVE-2025-34037","ts":1788883007000,"field":"exploit_available","old":"false","new":"true"},{"seq":1569,"id":"CVE-2025-34037","ts":1788882407254,"field":"exploit_available","old":"true","new":"false"},{"seq":683,"id":"CVE-2025-34037","ts":1788881843968,"field":"exploit_available","old":"false","new":"true"}]}