CVE-2026-108894 | Linksys E1700 1.0.0.4.003 Static Route /goform/addStaticRoute os command injection
A vulnerability has been found in Linksys E1700 1.0.0.4.003 and classified as very critical. Impacted is the function addStaticRoute of the file /goform/addStaticRoute of the component Static Route Handler. Performing a manipulation of the argument staticRoute_IP_setting/staticRoute_Netmask_setting/staticRoute_Gateway_setting/staticRoute_Metric_setting results in os command injection.
This vulnerability is known as CVE-2026-108894. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More