CVE-2025-9528
PoC ×2OS Command Injection in Linksys E1700 Router Firmware 1.0.0.4.003
Linksys E1700 router firmware version 1.0.0.4.003 contains an OS command injection flaw (CWE-77/CWE-78) in the systemCommand function of the /goform/systemCommand endpoint, where manipulation of the 'command' argument leads to execution of injected operating-system commands. The attack can be carried out remotely; the CVSS 4.0 vector indicates high privileges are required (PR:H), meaning the attacker needs an authenticated, admin-level session to trigger it. Successful exploitation lets an attacker run arbitrary OS commands on the device, which could enable configuration changes, credential theft, or full takeover of the router for uses such as botnet recruitment. The flaw affects Linksys E1700 devices running the disclosed 1.0.0.4.003 firmware; the vendor was contacted early but did not respond, so no fixed release is documented. A proof-of-concept exploit is publicly available, EPSS assigns a high 54.2% probability of exploitation within 30 days (99th percentile), but the issue is not yet listed in CISA KEV.
What to do: Check whether any E1700 devices in your estate run firmware 1.0.0.4.003 and treat them as affected, since the vendor did not respond and no patched firmware is documented. Because exploitation requires high privileges, limit the router's management interface to the LAN (disable WAN-side remote administration), enforce strong unique admin credentials, and monitor for a vendor advisory or firmware update. Given the high EPSS score and active IoT botnet campaigns targeting consumer routers, prioritize updating or replacing internet-exposed E1700 units.
| Linksys E1700 firmware | 1.0.0.4.003 (version named in the disclosure; no affected range or fixed version documented) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand. Executing manipulation of the argument command can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- linksys
- Products
- e1700 firmware
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X