Back to search
CVE-2013-10058
Published: Aug 1, 2025
Modified: Apr 7, 2026
PUBLISHED
Description
An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) running firmware version v2.0.03 via the apply.cgi endpoint. The web interface fails to properly sanitize user-supplied input passed to the ping_size parameter during diagnostic operations. An attacker with valid credentials can inject arbitrary shell commands, enabling remote code execution.
| Vendor | Product | Versions |
|---|---|---|
Linksys | WRT160nv2 | affected 2.0.03 |
Weaknesses (CWE)
References
https://web.archive.org/web/20140830181242/http://www.s3cur1ty.de/m1adv2013-012
technical-description
exploit
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now