{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3hlinksyse1200/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:linksys:e1200:*:*:*:*:*:*:*:*","cpe:2.3:o:linksys:e1200_firmware:2.0.11.001:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.4,"id":"CVE-2025-60689"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["E1200 (\u003c= 2.0.04)"],"_cs_severities":["high"],"_cs_tags":["webapps","cve-2025-60689","command-injection"],"_cs_type":"advisory","_cs_vendors":["Linksys"],"content_html":"\u003cp\u003eLinksys E1200 routers, specifically those running firmware version 2.0.04 and earlier, are susceptible to an unauthenticated OS command injection vulnerability (CVE-2025-60689). The vulnerability exists within the tmUnblock.cgi script, which fails to properly sanitize input provided to the ttcp_ip parameter during an HTTP POST request. By injecting shell metacharacters and commands into this parameter, an unauthenticated attacker can achieve arbitrary command execution with high privileges on the underlying Linux-based firmware. A proof-of-concept exploit is publicly available, which leverages this flaw to establish a reverse shell connection to an attacker-controlled listener. This vulnerability poses a significant risk to internal networks where these devices are deployed, as they often serve as the perimeter or routing gateway.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies a target Linksys E1200 device accessible over the network (LAN or WAN).\u003c/li\u003e\n\u003cli\u003eThe attacker prepares a payload containing a shell script string, such as a reverse shell setup using mkfifo and telnet.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts an HTTP POST request targeting the /tmUnblock.cgi endpoint.\u003c/li\u003e\n\u003cli\u003eThe malicious shell commands are injected into the ttcp_ip parameter within the request body.\u003c/li\u003e\n\u003cli\u003eThe router processes the POST data and passes the unsanitized ttcp_ip value to a system call.\u003c/li\u003e\n\u003cli\u003eThe injected commands execute with elevated privileges on the router.\u003c/li\u003e\n\u003cli\u003eThe final command (e.g., telnet) connects back to the attacker's listener, providing an interactive command shell.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full control of the router, potentially enabling an attacker to intercept network traffic, modify DNS settings, pivot into the internal network, or permanently disable the device. The vulnerability affects all Linksys E1200 devices running firmware version 2.0.04 or older, which are common in small office and home office (SOHO) environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eRestrict access to the router management interface to trusted internal IP addresses only.\u003c/li\u003e\n\u003cli\u003eIf a firmware update is unavailable from the vendor, isolate the affected Linksys E1200 device from public-facing segments.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall or IDS/IPS signatures to detect POST requests to /tmUnblock.cgi containing shell metacharacters in the ttcp_ip parameter.\u003c/li\u003e\n\u003cli\u003eMonitor for unexpected outbound connections from router hardware, particularly those utilizing the telnet protocol, as indicated in the CVE-2025-60689 exploit PoC.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-31T13:03:33Z","date_published":"2026-08-31T13:03:33Z","id":"https://feed.craftedsignal.io/briefs/2026-08-linksys-rce/","summary":"Linksys E1200 routers running firmware v2.0.04 and earlier are vulnerable to unauthenticated remote command execution via the tmUnblock.cgi endpoint.","title":"Unauthenticated OS Command Injection in Linksys E1200","url":"https://feed.craftedsignal.io/briefs/2026-08-linksys-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:h:linksys:e1200:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}