CVE-2013-10062
Linksys router <1.0.00-1.0.05 - Path Traversal
Title source: llmDescription
A directory traversal vulnerability exists in Linksys router's web interface (tested on the E1500 model firmware versions 1.0.00, 1.0.04, and 1.0.05), specifically in the /apply.cgi endpoint. Authenticated attackers can exploit the next_page POST parameter to access arbitrary files outside the intended web root by injecting traversal sequences. This allows exposure of sensitive system files and configuration data.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by m-1-k-3 · textwebappshardware
https://www.exploit-db.com/exploits/24475
References (4)
Scores
EPSS
0.4271
EPSS Percentile
97.4%
Classification
CWE
CWE-22
Status
draft
Timeline
Published
Aug 01, 2025
Tracked Since
Feb 18, 2026