See how linksys compares to other vendors in security performance
An unauthenticated command injection vulnerability exists in the StartEPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200v2.0.11.001us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wlant, wlssid, wlrate, ttcpnum, ttcpip, ttcpsize) are concatenated into system command strings without proper sanitization and executed via wlexeccmd. Successful exploitation allows remote attackers to execute arbitrary commands on the device without authentication.
A stack-based buffer overflow exists in the getmergeipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200v2.0.11.001us.tar.gz). The function concatenates up to four user-supplied CGI parameters matching <parameter>0~3 into a fixed-size buffer (a2) without bounds checking. Remote attackers can exploit this vulnerability via specially crafted HTTP requests to execute arbitrary code or cause denial of service without authentication.