{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3olinksysre7000_firmware2.0.15/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:linksys:re7000_firmware:2.0.15:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-86299"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RE7000 (2.0.15)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","network-security"],"_cs_type":"threat","_cs_vendors":["Linksys"],"content_html":"\u003cp\u003eCVE-2026-86299 describes a critical remote OS command injection vulnerability discovered in the Linksys RE7000 Wi-Fi range extender, specifically in firmware version 2.0.15. The vulnerability resides within the PingTest Handler component, managed by the platform_event_pingTest function in the /cgi-bin/json.cgi?PingTest endpoint. An attacker can supply malicious input via the pingTestIp, pingTestPktSize, or pingTestTimes arguments to execute arbitrary system commands with elevated privileges. Because the device is an internet-facing network component, this flaw presents a significant risk for unauthorized system access and device takeover. Public exploit material is currently available, increasing the likelihood of active exploitation. Defenders should monitor network traffic for anomalous POST or GET requests to the identified CGI binary and prioritize patching or isolating vulnerable devices.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full remote code execution on the affected Linksys RE7000 range extender. This enables attackers to gain administrative control over the networking hardware, potentially facilitating traffic interception, internal network reconnaissance, or pivoting into the local area network (LAN). As a consumer networking device, this impacts the integrity and availability of home and small office network infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately isolate vulnerable Linksys RE7000 devices (firmware 2.0.15) from the public internet if a firmware update is not yet available or has not been applied.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for HTTP requests targeting /cgi-bin/json.cgi?PingTest that contain shell metacharacters such as ';', '|', '\u0026amp;\u0026amp;', or '`' within the pingTestIp, pingTestPktSize, or pingTestTimes parameters.\u003c/li\u003e\n\u003cli\u003eDeploy firewall rules to block access to the management interface of networking devices from non-trusted or internet-facing networks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-07T12:52:51Z","date_published":"2026-09-07T12:52:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-linksys-rce/","summary":"An OS command injection vulnerability (CVE-2026-86299) in the Linksys RE7000 version 2.0.15 allows unauthenticated remote code execution via the PingTest Handler component.","title":"OS Command Injection in Linksys RE7000 Range Extender","url":"https://feed.craftedsignal.io/briefs/2026-09-linksys-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:linksys:re7000_firmware:2.0.15:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}