CVE-2013-3307 describes an OS command injection vulnerability in Linksys E1000, E1200, and E3200 routers, allowing attackers to execute arbitrary commands via shell metacharacters in the apply.cgi ping_ip parameter on TCP port 52000. This vulnerability carries a high CVSS score of 8.3, indicating a critical risk due to its network-based attack vector, low attack complexity, and potential for partial impact on confidentiality, integrity, and availability. While no direct Metasploit or Nuclei exploits are listed, an ExploitDB entry for a similar Linksys device suggests potential exploitability, and the vulnerability has been linked to the "BotenaGo" malware, indicating active exploitation in the wild. Community discussion and media coverage further highlight its relevance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linksys | E1200 | >= 0, < 2.0.05CNA affecteddefault unaffected | |
| Linksys | E3200 | >= 0, <= 1.0.04CNA affecteddefault unaffected | |
| Linksys | E1000 | >= 0, <= 2.1.02CNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.