CVE-2026-108896 | Linksys E1700 1.0.0.4.003 /goform/setLinksysIpv6 _6rd_prefix/_6rd_prefix_len os command injection
A vulnerability classified as very critical was found in Linksys E1700 1.0.0.4.003. This affects the function setLinksysIpv6 of the file /goform/setLinksysIpv6. The manipulation of the argument _6rd_prefix/_6rd_prefix_len results in os command injection.
This vulnerability is reported as CVE-2026-108896. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More