Linksys E1200 firmware 2.0.09 and Linksys E2500 firmware 3.0.04 contain an OS command injection vulnerability in handling of the Router Name setting. A value supplied through the web management portal is stored in NVRAM and later retrieved by the router startup logic. The value is incorporated directly into an operating-system command intended to write the hostname and is then executed without adequate filtering.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit auxiliary module targeting Linksys E1500 and E2500 routers vulnerable to authenticated OS command injection (CVE-2018-3953). The exploit requires valid credentials for the router's web interface (default: admin/admin or admin/password). It works by sending a crafted POST request to the /apply.cgi endpoint, injecting an arbitrary command (default: 'telnetd -p 1337') via the 'ping_size' parameter. The exploit is blind, meaning no output is returned from the executed command. The module is written in Ruby and is intended for use within the Metasploit framework. The structure is typical for a Metasploit module, with options for username, password, and command to execute. The main attack vector is network-based, targeting the router's HTTP interface.
This repository contains a single Metasploit module targeting Linksys E1500 and E2500 routers vulnerable to authenticated OS command injection (CVE-2018-3953) via the /apply.cgi HTTP endpoint. The exploit requires valid credentials for the router's web interface (default: admin/admin or admin/password). The module supports two payload types: direct command execution (CMD) and deployment of a custom MIPS ELF binary. The attack is performed by sending crafted POST requests to /apply.cgi, injecting commands into the 'ping_size' parameter. For binary payloads, the module sets up an HTTP server to deliver the ELF file, instructs the router to download it to /tmp/<random_filename>, sets executable permissions, and then executes it. The exploit provides remote code execution as root on the target device. The code is operational and leverages Metasploit's payload generation and HTTP server capabilities. The only file present is the Metasploit module itself, written in Ruby.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.