CVE-2025-34037 is an OS command injection vulnerability affecting multiple Linksys E-Series router models. CGI handlers exposed over HTTP on port 8080 process the user-controlled ttcp_ip parameter without sanitization, allowing unauthenticated remote attackers to inject shell commands and execute arbitrary code on the router. Other Linksys WAG, WAP, WES, WET, and WRT products and Wireless-N access points and routers may also be affected. TheMoon worm exploited the vulnerability in 2014 to deploy a MIPS ELF payload, and exploitation evidence was observed again on February 6, 2025.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit for unauthenticated command injection/RCE against vulnerable Linksys router CGI endpoints, primarily tmUnblock.cgi, with hndUnblock.cgi noted as an alternative. The repository contains only two files: a README describing the vulnerability, affected models, and usage, and a single executable script, exploit.py, which is the main entry point. The exploit works by crafting raw HTTP POST requests to the vulnerable CGI endpoint and injecting shell commands through the ttcp_ip form parameter. It percent-encodes the POST body, includes a Basic Authorization header with arbitrary credentials, and sends the request directly over a TCP socket to the target web service on port 80. The script first removes any previous payload from /tmp/c0d3z, then uploads an embedded base64-encoded MIPS little-endian ELF bind shell in 20-byte chunks using repeated echo -en commands with octal byte escapes. After staging, it chmods the file to make it executable, runs it via another injected command, waits briefly, and then connects to the bind shell on TCP port 4444. Capabilities include unauthenticated remote code execution, payload staging to the target filesystem, permission modification, payload execution, and an interactive post-exploitation shell over the bind socket. The exploit is operational rather than a simple proof of concept because it contains a complete hardcoded payload and an interactive shell handler. No external C2 infrastructure is used; all communication is direct between the attacker and the target router. The main fingerprintable artifacts are the vulnerable CGI paths, the temporary payload file /tmp/c0d3z, the default target IP 192.168.8.100, and the bind shell listener on port 4444.
This repository contains a single Metasploit module (modules/exploits/linux/http/linksys_themoon_exec.rb) that exploits a remote command injection vulnerability (CVE-2025-34037) in several Linksys E-Series routers. The exploit targets the /tmUnblock.cgi endpoint, which is accessible without authentication, and injects commands via the 'ttcp_ip' POST parameter. The module uses Metasploit's CmdStager to deliver staged payloads, typically resulting in a remote shell on the device. The exploit is weaponized, supporting both MIPS little-endian and big-endian architectures, and is effective against a range of Linksys routers, with E1500 v1.0.5 specifically tested. The code is structured as a standard Metasploit module, leveraging the HttpClient and CmdStager mixins for network communication and payload delivery.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability affecting Linksys devices through the ttcp_ip entry point. ClingSTUN includes a hard-coded exploit for self-propagation; successful in-the-wild exploitation is not separately confirmed.
A remote code execution vulnerability affecting Linksys devices. Cling embeds exploit logic targeting it; affected models and observed exploitation are not specified.
An additional vulnerability for which the analyzed Cling sample contains exploit code. The article does not individually identify its affected product or confirm successful exploitation in the wild.
Linksys vulnerability involving the ttcp_ip entry point, included in ClingSTUN's hard-coded propagation exploits. The report also associates it with administrative-console authentication bypass.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.