SANS researchers detected self-replicating work The Moon is spreading among a number of different Linksys routers. The Moon exploits an authentication bypassflaw in a CGI script in the administration interface. A Reddit user identified four CGI scripts that he believed were likely to be vulnerable. An exploit writer, who uses the online alias Rew, later confirmed that at least two of those scripts are vulnerable and published a proof-of-concept exploit. Linksys confirmed the presence of the vulnerability in its devices: Linksys will be working on the affected products with a firmware fix that is planned to be posted on our website in the coming weeks”]
Source: http://securityaffairs.co/wordpress/22345/hacking/exploit-linksys-routers-worm.html

