The latest firmware version 4.30.16 (build 4) remains vulnerable to the attack, dubbed Cross-Site File Upload (CSFU) In January of this year, Cisco (who owned Linksys until recently) published a patch to the router. The patch only addressed an unrelated XSS issue. The vulnerability tells me that this routers software was never given a security pen-test because it is just TOO easy! It only took 30 minutes to come to the conclusion that any network with an EA2700 router on it is an insecure network!”]
Source: https://superevr.com/blog/2013/dont-use-linksys-routers/