CVE-2025-5000
Linksys FGW3000-AH/FGW3000-HK HTTP POST Request sysconf.cgi control_panel_sw command injection
Description
A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000. It has been classified as critical. This affects the function control_panel_sw of the file /cgi-bin/sysconf.cgi of the component HTTP POST Request Handler. The manipulation of the argument filename leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
In plain language
AI Worth attentionCVE-2025-5000 is a remote command-injection flaw in some Linksys FGW3000-AH/FGW3000-HK router firmware that can let an attacker run commands via a crafted HTTP request; small businesses should treat it as a real patch-and-verify priority.
CVE-2025-5000 is a low-authentication network command-injection in Linksys FGW3000-AH/FGW3000-HK via sysconf.cgi control_panel_sw, triggered by manipulating the filename argument in an HTTP POST request handler, enabling remote unauthenticated/low-interaction command execution.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:LConfidentialityI:LIntegrityA:LAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-5000 and every CVE in our database. Create a free account — no credit card required.
Create Free Account