CVE-2013-10058
01.08.2025, 21:15
An authenticated OS command injection vulnerability exists in variousLinksys router models (tested on WRT160Nv2) running firmware version v2.0.03 via the apply.cgi endpoint. The web interface fails to properly sanitize user-supplied input passed to the ping_size parameter during diagnostic operations. An attacker with valid credentials can inject arbitrary shell commands, enabling remote code execution.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References