Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-7268 | An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) running firmware version v2.0.03 via the apply.cgi endpoint. The web interface fails to properly sanitize user-supplied input passed to the ping_size parameter during diagnostic operations. An attacker with valid credentials can inject arbitrary shell commands, enabling remote code execution. |
Thu, 20 Nov 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linksys wrt160nl
|
|
| CPEs | cpe:2.3:a:linksys:wrt160nl:2.0.03:*:*:*:*:*:*:* | |
| Vendors & Products |
Linksys wrt160nl
|
Wed, 06 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 Aug 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linksys
Linksys wrt160nv2 |
|
| Vendors & Products |
Linksys
Linksys wrt160nv2 |
Fri, 01 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) running firmware version v2.0.03 via the apply.cgi endpoint. The web interface fails to properly sanitize user-supplied input passed to the ping_size parameter during diagnostic operations. An attacker with valid credentials can inject arbitrary shell commands, enabling remote code execution. | |
| Title | Linksys Routers apply.cgi Remote Command Injection | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:03:12.433Z
Reserved: 2025-08-01T16:47:00.729Z
Link: CVE-2013-10058
Updated: 2025-08-06T14:05:53.996Z
Status : Deferred
Published: 2025-08-01T21:15:27.833
Modified: 2026-04-15T00:35:42.020
Link: CVE-2013-10058
No data.
OpenCVE Enrichment
Updated: 2025-08-05T11:39:03Z
EUVD