CVE-2025-9528 is an OS command injection vulnerability in the Linksys E1700 router, specifically affecting firmware version 1.0.0.4.003, through the systemCommand function in /goform/systemCommand. This flaw allows a remote attacker to execute arbitrary commands by manipulating the 'command' argument. Rated 7.2 HIGH on CVSS, it poses a significant risk with high impact on confidentiality, integrity, and availability, requiring high privileges for exploitation. While the exploit has been publicly disclosed, there is no evidence of active exploitation, nor are there readily available Metasploit, Nuclei, or ExploitDB modules, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0.4.003CPE matchmatch criteria | cpe:2.3:o:linksys:e1700_firmware:1.0.0.4.003:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.