CVE-2013-3307: Linksys e1000

High severity, CVSS 8.3. EPSS: 53.8% chance of exploitation in the next 30 days.

Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in the apply.cgi ping_ip parameter on TCP port 52000.

Affected products

  • Linksys e1000: up to and including 2.1.02
  • Linksys e1200: before 2.0.05 (fixed in 2.0.05)
  • Linksys e3200: up to and including 1.0.04

Published 2025-07-11. Last modified 2026-06-16.