Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 07 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injection. The attack can be launched remotely. The exploit is now public and may be used. | |
| Title | Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection | |
| First Time appeared |
Linksys
Linksys re7000 Firmware |
|
| Weaknesses | CWE-77 CWE-78 |
|
| CPEs | cpe:2.3:o:linksys:re7000_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Linksys
Linksys re7000 Firmware |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-07T11:15:07.784Z
Reserved: 2026-09-06T16:32:18.951Z
Link: CVE-2026-86299
No data.
No data.
No data.
OpenCVE Enrichment
No data.
