CVE-2026-108895 | Linksys E1700 1.0.0.4.003 /goform/setDMZ MAC_addr os command injection
A vulnerability was found in Linksys E1700 1.0.0.4.003 and classified as very critical. The affected element is the function setDMZ of the file /goform/setDMZ. Executing a manipulation of the argument MAC_addr can lead to os command injection.
This vulnerability is handled as CVE-2026-108895. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More