CVE-2013-10062: Linksys e1500

Medium severity, CVSS 6.9. EPSS: 2.1% chance of exploitation in the next 30 days.

A directory traversal vulnerability exists in Linksys router's web interface (tested on the E1500 model firmware versions 1.0.00, 1.0.04, and 1.0.05), specifically in the /apply.cgi endpoint. Authenticated attackers can exploit the next_page POST parameter to access arbitrary files outside the intended web root by injecting traversal sequences. This allows exposure of sensitive system files and configuration data.

Affected products

  • Linksys e1500: version 1.0.00 only; version 1.0.04 only; version 1.0.05 only

Published 2025-08-01. Last modified 2026-06-16.