CVE-2026-86299 PUBLISHED

Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection

Assigner: VulDB
Reserved: 06.09.2026 Published: 07.09.2026 Updated: 07.09.2026

A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injection. The attack can be launched remotely. The exploit is now public and may be used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
CVSS Score: 9.4

Product Status

Vendor Linksys
Product RE7000
Versions
  • Version 2.0.15 is affected

Credits

  • sleep (VulDB User) reporter

References

Problem Types

  • OS Command Injection CWE
  • Command Injection CWE