Skip to main content
QUIETLYTIC
Vulnerability

Linksys RE7000 2.0.15 Command Injection (CVE-2026-86299)

CVE-2026-86299 is a CVSS 9.9 critical OS command injection in Linksys RE7000 firmware, reachable remotely via the PingTest handler, with public exploit code available.

CVE-2026-86299
Threat Level
CRITICAL
CVSS
9.9
Status
Monitored
Confidence
Medium
Affected Products
Linksys RE7000 2.0.15

CVE-2026-86299 is a critical (CVSS 3.1 base 9.9) OS command injection vulnerability in the Linksys RE7000 Wi-Fi range extender, version 2.0.15.

What the vulnerability does

Per NVD’s description, the flaw sits in the platform_event_pingTest function of /cgi-bin/json.cgi?PingTest, the device’s PingTest handler. The pingTestIp, pingTestPktSize, and pingTestTimes parameters are passed into a command without adequate sanitization, allowing an attacker to inject arbitrary OS commands. NVD’s own description states the attack can be launched remotely and that exploit code is now public.

The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) shows a network-reachable, low-complexity flaw requiring low privileges and no user interaction, with a changed scope and high impact across confidentiality, integrity, and availability — consistent with full command execution on the device.

Public exploit availability vs. confirmed exploitation

NVD’s description notes public exploit code exists for this vulnerability — a materially different claim from confirmed in-the-wild exploitation. As of this writing, CVE-2026-86299 is not listed in CISA’s Known Exploited Vulnerabilities catalog, which CISA reserves for vulnerabilities with confirmed active exploitation evidence, not merely public proof-of-concept availability. Both facts matter: public exploit code substantially lowers the bar for opportunistic attackers, even without a confirmed KEV listing.

What we don’t yet have

This record traces to a single source (NVD); no independent vendor advisory or second-source corroboration is present in our ingested data, so confidence is medium. We also don’t have confirmation of a patched firmware version — Linksys’s own advisory should be checked directly for remediation guidance.

Why this matters

The combination of a “low privilege required, no user interaction” network-reachable command injection with publicly available exploit code makes internet-exposed RE7000 units running 2.0.15 a realistic, low-effort target. Consumer/SOHO network hardware exposed to the internet is a persistent botnet-recruitment target precisely because of vulnerabilities in this class — administrators should confirm firmware version and restrict remote management access regardless of patch availability.

Frequently Asked Questions

What is CVE-2026-86299? A CVSS 9.9 critical OS command injection vulnerability in Linksys RE7000 firmware version 2.0.15, reachable remotely via the device’s PingTest diagnostic handler.

Is exploit code available for CVE-2026-86299? Yes, per NVD’s description — public exploit code exists, though this is distinct from confirmed active exploitation.

Is CVE-2026-86299 listed in CISA’s KEV catalog? No, not as of this writing.


Data sourced from the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)

Related intelligence


Analyst tools