Vulnary
← back to the feed
Critical· 10

CVE-2025-34037

An OS command injection flaw in certain Linksys routers allows attackers to run arbitrary shell commands without authentication. The vulnerability is triggered through the /tmUnblock.cgi and /hndUnblock.cgi web endpoints on port 8080. It has been exploited in the wild, notably by the "TheMoon" worm in 2014.

publishedJun 24, 2025
last modifiedJul 22, 2026
sourcesNVD
severity · cvss
10
critical · how bad it is
exploitation · epss
86%
100th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 5, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Linksys E‑Series routers accessed via /tmUnblock.cgi and /hndUnblock.cgi on HTTP port 8080, and potentially other Linksys models such as WAG, WAP, WES, WET, WRT series and Wireless‑N access points.

02

Real-world impact

An attacker can execute any shell command on the router, giving full control over the device, including installing malware, redirecting traffic, or using the router as a launch point for further attacks.

03

Why this severity

The CVSS score of 10 reflects that the flaw is exploitable without authentication, allows complete compromise of the router, and has a high impact on confidentiality, integrity, and availability.

04

What to do about it

no official fix yet

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

No fix documented in sources

05

Timeline

  1. Jun 24, 2025 · Jun 24, 2025
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 22, 2026 · 14d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →