CVE-2025-9146 is a high-severity vulnerability (CVSS 8.1) affecting Linksys E5600 firmware version 1.1.0.26, specifically within the 'verify_gemtek_header' function of the 'checkFw.sh' component. This flaw involves the use of a risky cryptographic algorithm, allowing for remote manipulation that could lead to high impact on confidentiality, integrity, and availability. While the attack is remotely launchable and requires no user interaction, its complexity is high, and exploitability is considered difficult. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.0.26CPE matchmatch criteria | cpe:2.3:o:linksys:e5600_firmware:1.1.0.26:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.