Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Linksys

First CVE: Jul 21, 2001Active for: 25 yearsTotal CVEs: 223
56.6
VTI Score
TOP TARGET

Linksys's vulnerability footprint centers on a broadly represented range of consumer and small-business networking devices, particularly mesh Wi-Fi extenders and routers such as the RE6500, RE7000, and RE6300 lines, which are widely deployed in residential and office networks. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency to acquire public exploit code, reflecting the appeal of internet-facing network appliances as targets for remote compromise and lateral movement. The exposure recurs across firmware releases through weakness classes including command injection, OS command injection, and buffer overflow conditions that are characteristic of embedded systems with limited memory protections and extensive command-handling interfaces. Defenders should prioritize patching these devices, particularly those exposed to untrusted networks, and inventory end-of-life models that may lack security updates; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
223
Total CVEs
More Total CVEs than 100% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Linksys over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 21, 2001
25 years ago
Most Recent CVE
Apr 25, 2026
90 days ago

Products(143 total)

Top CVEs

Signals from CVEs in this vendor scope (223 CVEs).

223 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-17411CRITICAL
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The
Dec 21, 20179.889NOYES
CVE-2005-2799HIGH
Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote attackers to execute arbitrary code via a long HTTP POST re
Sep 15, 20057.575NOYES
CVE-2020-35713CRITICAL
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.
Dec 26, 20209.857NOYES
CVE-2024-27497HIGH
Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.
Mar 1, 20248.853NOYES
CVE-2025-9528HIGH
A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand. Executing manipulation of the
Aug 27, 20257.251NONO
CVE-2025-60690HIGH
A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatena
Nov 13, 20258.845NOYES
CVE-2022-38841HIGH
Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page.
Apr 16, 20238.844NOYES
CVE-2025-5447CRITICAL
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. Th
Jun 2, 20259.843NONO
CVE-2024-25852HIGH
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use th
Apr 11, 20248.843NOYES
CVE-2025-5446CRITICAL
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been classified as critical.
Jun 2, 20259.841NONO
View all 223 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products223 CVEs
26%
59%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local9 (4.0%)
Network124 (55.6%)
Unknown63 (28.3%)
Physical3 (1.3%)
Adjacent Network24 (10.8%)
Attack Complexity
Low159 (71.3%)
High1 (0.4%)
Unknown63 (28.3%)
User Interaction
None148 (66.4%)
Unknown63 (28.3%)
Required12 (5.4%)
Privileges Required
Low83 (37.2%)
High13 (5.8%)
None64 (28.7%)
Unknown63 (28.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (223 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
1.8% of CVEs· 97th percentile
Nuclei
3 CVEs
1.3% of CVEs· 95th percentile
ExploitDB
18 CVEs
8.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Linksys.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Linksys — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Linksys's Products

View all 10 CNAs →

Top CWEs