← Vulnerability feed

Vulnerability record · CVE-2025-9528 · published 27 August 2025

CVE-2025-9528: Linksys E1700 systemCommand OS command injection

Linksys · E1700 Firmware

The Linksys E1700 firmware 1.0.0.4.003 exposes the /goform/systemCommand endpoint, where the systemCommand function passes a user-supplied command argument into an OS command without sanitization. An authenticated remote attacker can inject arbitrary commands, and a public proof-of-concept exploit exists while the vendor did not respond to disclosure.

2.0 CVSS 4.0 Low EPSS 54% · top 1.0% CWE-77 · Command injectionCWE-78 · OS command injection
2.0CVSS 4.0 base score, v2 5.8
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand. Executing manipulation of the argument command can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

medium priorityThe CVSS 4.0 base score is only 2 (LOW) because high privileges are required, but a public exploit and very high EPSS (98.9th percentile) raise the practical risk for exposed, unpatched devices.

What it is

The Linksys E1700 firmware 1.0.0.4.003 exposes the /goform/systemCommand endpoint, where the systemCommand function passes a user-supplied command argument into an OS command without sanitization. An authenticated remote attacker can inject arbitrary commands, and a public proof-of-concept exploit exists while the vendor did not respond to disclosure.

Impact

An attacker with valid credentials gains remote command execution on the router, allowing arbitrary commands to run with the privileges of the affected service. This can lead to full device compromise, configuration changes, or use of the router as a pivot into the local network.

Attack surface

The flaw is reached over the network via the /goform/systemCommand HTTP endpoint, requiring high privileges (PR:H) per the CVSS vector, meaning valid administrative authentication is needed. No user interaction is required (UI:N).

Exploitation

Public exploit code is referenced with Exploit tags, and EPSS is 0.5419 (98.9th percentile), indicating a high likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild campaigns are documented in this record.

What to do

  • Apply any firmware update from Linksys for the E1700 if one becomes available; the vendor did not respond to the disclosure, so confirm support status directly.
  • If no patch exists, restrict administrative access to the router web interface to trusted management networks only and disable remote/WAN administration.
  • Change default administrative credentials and enforce strong unique passwords to reduce the PR:H barrier.
  • Place the device behind a firewall that blocks external access to /goform/ endpoints and monitor for unusual outbound traffic from the router.
  • Consider replacing or isolating end-of-support hardware that receives no vendor fixes.

Detection

  • Monitor router and upstream logs for POST requests to /goform/systemCommand with unexpected command parameters.
  • Alert on shell metacharacters (;, |, &, $(), backticks) in HTTP request bodies or query strings targeting the router management interface.
  • Watch for anomalous outbound connections or processes spawned by the router's web service, which may indicate injected command execution.
  • Audit authentication logs for successful admin logins from unusual source IPs preceding requests to /goform/ endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/wudipjq/my_vuln/blob/main/Linksys2/vuln_61/61.md ExploitThird Party Advisory
https://github.com/wudipjq/my_vuln/blob/main/Linksys2/vuln_61/61.md#poc ExploitThird Party Advisory
https://vuldb.com/?ctiid.321545 Permissions RequiredVDB Entry
https://vuldb.com/?id.321545 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.634827 Third Party AdvisoryVDB Entry
https://www.linksys.com/ Product

Track CVE-2025-9528 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.0CVE-2024-22544Linksys e1700 firmware command injection vulnerabilityAn issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTim…EPSS 9.3%7.4CVE-2025-9527Linksys e1700 firmware memory buffer overflow vulnerabilityA vulnerability was found in Linksys E1700 1.0.0.4.003. This affects the function QoSSetup of the file /goform/QoSSetup. Performing manipulation of t…EPSS 1.5%7.4CVE-2025-9525Linksys e1700 firmware memory buffer overflow vulnerabilityA flaw has been found in Linksys E1700 1.0.0.4.003. Affected by this vulnerability is the function setWan of the file /goform/setWan. This manipulati…EPSS 1.4%7.4CVE-2025-9526Linksys e1700 firmware memory buffer overflow vulnerabilityA vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the file /goform/setSysAdm. Such man…EPSS 1.4%6.1CVE-2024-22543Linksys e1700 firmware insufficient session expiration vulnerabilityAn issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET request to …EPSS 1.2%9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2025-9528), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.