A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000. It has been classified as critical. This affects the function control_panel_sw of the file /cgi-bin/sysconf.cgi of the component HTTP POST Request Handler. The manipulation of the argument filename leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
In plain language
Written by AI from the record
CVE-2025-5000 is a remote command-injection flaw in some Linksys FGW3000-AH/FGW3000-HK router firmware that can let an attacker run commands via a crafted HTTP request; small businesses should treat it as a real patch-and-verify priority.
CVE-2025-5000 is a low-authentication network command-injection in Linksys FGW3000-AH/FGW3000-HK via sysconf.cgi control_panel_sw, triggered by manipulating the filename argument in an HTTP POST request handler, enabling remote unauthenticated/low-interaction command execution.
If you're affected
Device takeover
Malware installation
Traffic redirection or interception
Service disruption
What is it
This bug lets an attacker send a specially crafted web request to the router, and the router may end up running attacker-chosen commands. Think of it like someone finding a way to whisper instructions into your front door system so your building acts on them. If exploited, the attacker could interfere with your network or install unwanted changes.
Who is affected
This matters if you run or manage Linksys FGW3000-AH or FGW3000-HK routers (including the fgw3000-ah and fgw3000-hk firmware lines). Because the attack happens over the network and needs low authentication with no user interaction, a publicly reachable router is the most concerning scenario. If the vulnerable web/CGI endpoint isn’t reachable from outside your local network, the risk is lower—focus on whether it’s exposed to the internet or otherwise accessible from untrusted networks.
How urgent is it
Treat this as an immediate priority for patching/containment because attackers can send remote HTTP POST requests that lead to command injection, and exploitation has been publicly disclosed. The current evidence is not listed as CISA KEV, but the public Proof-of-Concept means it is realistic to attempt against exposed devices. Because the weakness is low-complexity to trigger and requires no user interaction, you should act now to reduce exposure and apply the fixed firmware once available.
What to do — in detail
Confirm exposure (affected model + access path)
Identify whether the business uses Linksys FGW3000-AH or FGW3000-HK.
Record the current firmware version.
Determine whether the router’s HTTP web/CGI services are reachable from outside your local network (internet):
Check your WAN/public exposure settings.
Look for any port-forwarding or “remote management” features.
If you’re unsure, have IT test from an external network (not your office Wi‑Fi/LAN) to see if the admin/web pages respond.
Confirm whether the version is in the vulnerable range
The backstop indicates “up to 1.0.17.000000,” so treat versions at or below that level as potentially vulnerable until your vendor provides the exact fixed build for your branch.
Because the provided findings do not include a definitive fixed version number, request the exact “fixed in ” from Linksys support / your vendor and map it to your firmware line.
Apply the fix
Upgrade to the vendor’s fixed firmware release that addresses CVE-2025-5000 for your model.
Plan for the router to reboot and verify that WAN connectivity and critical business services (VPN, remote access, VoIP, payment systems) still work after upgrade.
If patching is delayed: block remote reachability immediately
Implement network controls to prevent inbound connections from the internet to the router’s web/CGI endpoint(s) (including sysconf.cgi/control_panel_sw).
Use firewall rules or upstream firewall policies so the router is only reachable from your local network.
Remove or disable any port-forwarding and remote administration features that are not strictly required.
Post-change verification
Re-check that external networks cannot access the router’s web interface/CGI endpoints.
Review router logs for unusual HTTP POST requests to /cgi-bin/sysconf.cgi.
Monitor for unexpected configuration changes and suspicious outbound traffic from the router for at least the next several days.
Public disclosure readiness
A public Proof-of-Concept exists, so assume that attackers may attempt the bug on any exposed device.
CISA KEV timing
Not listed in CISA KEV in the provided findings, so there is no KEV-driven deadline here.
Technical context
CVE-2025-5000 is an HTTP command injection (CWE-74 and CWE-77) affecting Linksys FGW3000-AH and FGW3000-HK firmware lines. The mechanism is a crafted HTTP POST request to /cgi-bin/sysconf.cgi, where the control_panel_sw function is tricked by manipulating the filename argument, resulting in execution of attacker-controlled commands on the device. The findings indicate low authentication is required and no user interaction is needed; remote network exploitation is feasible.
Exploitation status and maturity
CISA KEV: not listed.
Public exploit: a Proof-of-Concept exists (public PoC on GitHub), and the findings describe “may be used.” That increases the practical risk for exposed devices.
Likelihood indicators
EPSS is reported as rising in the findings; this is a prediction only and not proof of widespread exploitation.
Severity
The backstop describes the issue as critical in the vendor’s classification, while the provided CVSS is 6.3 (medium). For operators, the practical risk is driven more by remote reachability and whether the HTTP/CGI endpoint is exposed to untrusted networks.
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.