Vulnerability record · CVE-2025-9528 · published 27 August 2025
CVE-2025-9528: Linksys E1700 systemCommand OS command injection
Linksys · E1700 Firmware
The Linksys E1700 firmware 1.0.0.4.003 exposes the /goform/systemCommand endpoint, where the systemCommand function passes a user-supplied command argument into an OS command without sanitization. An authenticated remote attacker can inject arbitrary commands, and a public proof-of-concept exploit exists while the vendor did not respond to disclosure.
Description
A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand. Executing manipulation of the argument command can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
medium priorityThe CVSS 4.0 base score is only 2 (LOW) because high privileges are required, but a public exploit and very high EPSS (98.9th percentile) raise the practical risk for exposed, unpatched devices.
What it is
The Linksys E1700 firmware 1.0.0.4.003 exposes the /goform/systemCommand endpoint, where the systemCommand function passes a user-supplied command argument into an OS command without sanitization. An authenticated remote attacker can inject arbitrary commands, and a public proof-of-concept exploit exists while the vendor did not respond to disclosure.
Impact
An attacker with valid credentials gains remote command execution on the router, allowing arbitrary commands to run with the privileges of the affected service. This can lead to full device compromise, configuration changes, or use of the router as a pivot into the local network.
Attack surface
The flaw is reached over the network via the /goform/systemCommand HTTP endpoint, requiring high privileges (PR:H) per the CVSS vector, meaning valid administrative authentication is needed. No user interaction is required (UI:N).
Exploitation
Public exploit code is referenced with Exploit tags, and EPSS is 0.5419 (98.9th percentile), indicating a high likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild campaigns are documented in this record.
What to do
- Apply any firmware update from Linksys for the E1700 if one becomes available; the vendor did not respond to the disclosure, so confirm support status directly.
- If no patch exists, restrict administrative access to the router web interface to trusted management networks only and disable remote/WAN administration.
- Change default administrative credentials and enforce strong unique passwords to reduce the PR:H barrier.
- Place the device behind a firewall that blocks external access to /goform/ endpoints and monitor for unusual outbound traffic from the router.
- Consider replacing or isolating end-of-support hardware that receives no vendor fixes.
Detection
- Monitor router and upstream logs for POST requests to /goform/systemCommand with unexpected command parameters.
- Alert on shell metacharacters (;, |, &, $(), backticks) in HTTP request bodies or query strings targeting the router management interface.
- Watch for anomalous outbound connections or processes spawned by the router's web service, which may indicate injected command execution.
- Audit authentication logs for successful admin logins from unusual source IPs preceding requests to /goform/ endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/wudipjq/my_vuln/blob/main/Linksys2/vuln_61/61.md | ExploitThird Party Advisory |
| https://github.com/wudipjq/my_vuln/blob/main/Linksys2/vuln_61/61.md#poc | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.321545 | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.321545 | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.634827 | Third Party AdvisoryVDB Entry |
| https://www.linksys.com/ | Product |
Track CVE-2025-9528 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-9528), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.