CVE-2025-34037 | Linksys E900 Service Port 8080 /tmUnblock.cgi ttcp_ip TheMoon os command injection (EUVD-2025-18964 / EDB-31683)
A vulnerability classified as very critical was found in Linksys E4200, E3200, E3000, E2500, E2100L, E2000, E1550, E1500, E1200, E1000 and E900. This vulnerability affects unknown code of the file /tmUnblock.cgi of the component Service Port 8080. The manipulation of the argument ttcp_ip leads to os command injection.
This vulnerability was named CVE-2025-34037. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.