<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>RE7000 (2.0.15) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/re7000-2.0.15/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 07 Sep 2026 12:52:51 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/re7000-2.0.15/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>OS Command Injection in Linksys RE7000 Range Extender</title><link>https://feed.craftedsignal.io/briefs/2026-09-linksys-rce/</link><pubDate>Mon, 07 Sep 2026 12:52:51 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-linksys-rce/</guid><description>An OS command injection vulnerability (CVE-2026-86299) in the Linksys RE7000 version 2.0.15 allows unauthenticated remote code execution via the PingTest Handler component.</description><content:encoded><![CDATA[<p>CVE-2026-86299 describes a critical remote OS command injection vulnerability discovered in the Linksys RE7000 Wi-Fi range extender, specifically in firmware version 2.0.15. The vulnerability resides within the PingTest Handler component, managed by the platform_event_pingTest function in the /cgi-bin/json.cgi?PingTest endpoint. An attacker can supply malicious input via the pingTestIp, pingTestPktSize, or pingTestTimes arguments to execute arbitrary system commands with elevated privileges. Because the device is an internet-facing network component, this flaw presents a significant risk for unauthorized system access and device takeover. Public exploit material is currently available, increasing the likelihood of active exploitation. Defenders should monitor network traffic for anomalous POST or GET requests to the identified CGI binary and prioritize patching or isolating vulnerable devices.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for full remote code execution on the affected Linksys RE7000 range extender. This enables attackers to gain administrative control over the networking hardware, potentially facilitating traffic interception, internal network reconnaissance, or pivoting into the local area network (LAN). As a consumer networking device, this impacts the integrity and availability of home and small office network infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately isolate vulnerable Linksys RE7000 devices (firmware 2.0.15) from the public internet if a firmware update is not yet available or has not been applied.</li>
<li>Monitor network traffic for HTTP requests targeting /cgi-bin/json.cgi?PingTest that contain shell metacharacters such as ';', '|', '&amp;&amp;', or '`' within the pingTestIp, pingTestPktSize, or pingTestTimes parameters.</li>
<li>Deploy firewall rules to block access to the management interface of networking devices from non-trusted or internet-facing networks.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>vulnerability</category><category>rce</category><category>network-security</category></item></channel></rss>