CVE-2025-34037

CRITICAL EXPLOITED

Linksys E-Series - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-34037 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 3 public exploits from researchers including Rew, Taxanehh, Johannes Ullrich, Rew, infodox, including a Metasploit module exploits/linux/http/linksys_themoon_exec.

AI-analyzed exploit summary This exploit targets an unauthenticated remote code execution vulnerability in various Linksys routers by leveraging a command injection flaw in the tmUnblock.cgi endpoint. It writes a MIPSEL shellcode payload to the filesystem and executes it to establish a bind shell on port 4444.

Description

An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability was reported to be exploited in the wild by the "TheMoon" worm  in 2014 to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. Additionally, this vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Rew · phpremotehardware
https://www.exploit-db.com/exploits/31683

This exploit targets an unauthenticated remote code execution vulnerability in various Linksys routers by leveraging a command injection flaw in the tmUnblock.cgi endpoint. It writes a MIPSEL shellcode payload to the filesystem and executes it to establish a bind shell on port 4444.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Linksys routers (multiple models, firmware unspecified)
No auth needed
Prerequisites: Network access to the target router's web interface (port 8080) · Vulnerable Linksys router model
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by Taxanehh · poc
https://github.com/Taxanehh/CVE-2025-34037

This repository contains a functional Python exploit for CVE-2025-34037, targeting a command injection vulnerability in the tmUnblock.cgi endpoint of various Linksys router models. The exploit stages a MIPS bind shell onto the target device and provides an interactive shell.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Linksys routers (multiple models including E4200, E3200, E3000, etc.)
No auth needed
Prerequisites: Network access to the target router · tmUnblock.cgi or hndUnblock.cgi endpoint exposed
devstral-2 · analyzed Apr 09, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Johannes Ullrich, Rew, infodox · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/linksys_themoon_exec.rb

This Metasploit module exploits an unauthenticated OS command injection vulnerability in Linksys E-Series routers (CVE-2025-34037), leveraging the 'ttcp_ip' parameter in a POST request to '/tmUnblock.cgi' to execute arbitrary commands. It supports MIPS-based payloads and was tested against E1500 v1.0.5.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Linksys E-Series Routers (E4200, E3200, E3000, E2500, E2100L, E2000, E1550, E1500, E1200, E1000, E900)
No auth needed
Prerequisites: Network access to the vulnerable router · Vulnerable firmware version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Various Sources technical-description
https://isc.sans.edu/diary/17633
Exploit, Third Party Advisory third-party-advisory exploit
https://www.exploit-db.com/exploits/31683
Third Party Advisory third-party-advisory
https://vulncheck.com/advisories/linksys-routers-command-injection

Scores

CVSS v4 10.0
EPSS 0.8927
EPSS Percentile 99.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2025-06-23
CWE
CWE-78
Status published
Products (11)
Linksys/E1000 v1 < 2.1.03
Linksys/E1200 v1 < 1.0.04
Linksys/E1500 v1 < 1.0.06
Linksys/E1550 < 1.0.03
Linksys/E2000
Linksys/E2100L v1 < 1.0.05
Linksys/E2500 v1/v2 < 2.0.00
Linksys/E3000 < 1.0.06
Linksys/E3200 < 1.0.05
Linksys/E4200 < 1.0.06
... and 1 more
Published Jun 24, 2025
Tracked Since Feb 18, 2026