A public proof-of-concept exists for CVE-2026-86299, a remotely exploitable OS command injection flaw in the Linksys RE7000 range extender's PingTest handler carrying a CVSS 3.1 score of 9.9 (Critical).
What Is It
CVE-2026-86299 is an OS command injection vulnerability (CWE-77, CWE-78) in Linksys RE7000 firmware version 2.0.15. The flaw lives in the platform_event_pingTest function, reached through /cgi-bin/json.cgi?PingTest in the PingTest Handler component. An attacker who manipulates the pingTestIp, pingTestPktSize, or pingTestTimes arguments can inject operating system commands. The attack can be launched remotely, and per NVD the exploit is now public and may be used.
Why It Matters
The CVSS 3.1 vector, AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, describes a network-reachable, low-complexity attack that needs only low privileges and no user interaction. The changed scope, combined with high confidentiality, integrity, and availability impact, is what pushes the score to 9.9. The CVSS 4.0 assessment from the same CNA rates it 8.6 (High) and explicitly sets exploit maturity to Proof-of-Concept. In practical terms: an attacker with minimal access to the device's web interface can execute arbitrary commands on a network appliance that sits inline with client traffic.
The supplied source material reports a published proof-of-concept and does not document confirmed exploitation in the wild.
What's Vulnerable
- Vendor: Linksys
- Product: RE7000
- Affected version: firmware 2.0.15 (
cpe:2.3:o:linksys:re7000_firmware) - Component: PingTest Handler, via
/cgi-bin/json.cgi?PingTest
No other versions or products are listed in the supplied record.
Patch Status
The supplied source material contains no vendor advisory, patched version, or fix reference. The only vendor-associated link is the Linksys homepage. Until Linksys publishes guidance, treat the device's management interface as exposed: restrict access to it, and do not reach it from untrusted networks.
Sources
- NVD, CVE-2026-86299: https://nvd.nist.gov/vuln/detail/CVE-2026-86299
- VulDB, CVE-2026-86299: https://vuldb.com/cve/CVE-2026-86299
- VulDB, Vulnerability 399463: https://vuldb.com/vuln/399463
- VulDB, Threat intelligence (399463): https://vuldb.com/vuln/399463/cti
- Public write-up (limou89/somevul): https://github.com/limou89/somevul/blob/main/Linksys_RE7000_v2_PingTest_Command_Injection.md
- Linksys: https://www.linksys.com/