Two dozen Linksys router models are vulnerable to attacks that could extract sensitive information from their configurations. The vulnerabilities were discovered by senior security consultant Tao Sauvage from IOActive and independent security researcher Antide Petit. The flaws range from low to high severity and directly impact over 7,000 routers that have their web-based administrative interfaces exposed to the Internet. The most serious vulnerability could allow attackers to inject and execute shell commands with root privileges on the affected routers. The vulnerability could be used to set up a backdoor administrative account that wouldn’t be listed in the web interface.”]