← back
CVE-2025-9528mediumobserved exploitationCWE-77CWE-78

Linksys E1700 systemCommand os command injection

47Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendcvss 5.1epss 48%
from disclosure to weapon
Published on NVDAug 27
VulnCheck+89d
exploitation probability
48%top 1% of all CVEs
observed exploitation
yesVulnCheck
A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand. Executing manipulation of the argument command can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
Linksys · E1700