CVE-2025-4999: Linksys FGW3000-AH/FGW3000-HK HTTP POST Request sysconf.cgi sub_4153FC command injection
A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000 and classified as critical. Affected by this issue is the function sub4153FC of the file /cgi-bin/sysconf.cgi of the component HTTP POST Request Handler. The manipulation of the argument supplicantrndiden leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4999?
CVE-2025-4999 is classified as a critical vulnerability.
How do I fix CVE-2025-4999?
To fix CVE-2025-4999, update the Linksys FGW3000-AH and FGW3000-HK to a version higher than 1.0.17.000000.
What impact does CVE-2025-4999 have?
CVE-2025-4999 may allow unauthorized access or manipulation of the device through its HTTP POST Request Handler.
Which devices are affected by CVE-2025-4999?
CVE-2025-4999 affects Linksys FGW3000-AH and FGW3000-HK routers up to version 1.0.17.000000.
What is the nature of the vulnerability in CVE-2025-4999?
CVE-2025-4999 involves a manipulation vulnerability in the function sub_4153FC of the file /cgi-bin/sysconf.cgi.