---
id: CVE-2025-34037
title: "An OS command injection vulnerability exists in various models of E-Series Linksys\_routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080"
summary: "An OS command injection vulnerability exists in various models of E-Series Linksys\_routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the …"
severity: none
cwe:
  - CWE-78
published: '2025-06-24'
updated: '2026-07-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34037'
references:
  - url: 'https://isc.sans.edu/diary/17633'
    label: disclosure@vulncheck.com
  - url: 'https://vulncheck.com/advisories/linksys-routers-command-injection'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/31683'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Jarrettgohxz/CVE-research/tree/main/Linksys/E-series/CVE-2025-34037
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.90939
epssPercentile: 0.99804
ingestedAt: '2026-07-22T17:05:16.163Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/Taxanehh/CVE-2025-34037'
  metasploit:
    - exploit/linux/http/linksys_themoon_exec
  checkedAt: '2026-09-25T08:20:45.109Z'
exploitAvailable: true
---

## Overview

An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability was reported to be exploited in the wild by the "TheMoon" worm  in 2014 to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. Additionally, this vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
