ZeroHour

CVE-2026-86299

large

OS Command Injection in Linksys RE7000 Range Extender PingTest Handler

CVSS 4.0
8.6 high
EPSS
2%p79
Published
()
Modified
AI analysis

CVE-2026-86299 is an OS command injection flaw in the PingTest handler of the Linksys RE7000 Wi-Fi range extender, in the platform_event_pingTest function reached via the /cgi-bin/json.cgi?PingTest endpoint on firmware 2.0.15. An attacker who can reach the device's web interface supplies crafted values in the pingTestIp, pingTestPktSize, or pingTestTimes parameters, and because those values are passed to a shell without sanitization, arbitrary operating-system commands are executed (CWE-77/CWE-78). The CVSS 4.0 score of 8.6 (High) shows the attack is launched remotely but requires low-privilege access (PR:L), meaning valid or default credentials for the management interface, and the High impact ratings across confidentiality, integrity, and availability indicate effective full compromise of the device. Anyone running a Linksys RE7000 on firmware 2.0.15 is affected; units whose admin interface is internet-exposed or that still use default credentials are the most likely targets. The exploit is described as publicly available and may be used, though no detailed PoC is catalogued; the issue is not in CISA's KEV and EPSS estimates roughly a 2% chance of exploitation within 30 days (79th percentile).

What to do: Check Linksys support for RE7000 firmware newer than 2.0.15 and upgrade as soon as a fixed release is published (no fixed version is given in the available data). Until then, keep the extender's management interface off the internet, ensure strong non-default admin credentials, and monitor for anomalous values in pingTestIp, pingTestPktSize, or pingTestTimes in requests to /cgi-bin/json.cgi?PingTest, which would indicate exploitation attempts.

Affected
Linksys RE7000 Wi-Fi range extender2.0.15 (version cited in the advisory; other firmware versions not specified in the data)
Estimated exposure
large≈ hundreds of thousands of consumer units in use (order-of-magnitude estimate; count of internet-exposed devices unknown) — The RE7000 is a mainstream consumer Wi-Fi extender sold by a major retail networking vendor over multiple years, making an installed base in the 100k-1M range plausible, but only devices whose web management interface is reachable (LAN or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injection. The attack can be launched remotely. The exploit is now public and may be used.

Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.