Medium severity4.7NVD Advisory· Published Aug 27, 2025· Updated Jun 17, 2026
CVE-2025-9528
CVE-2025-9528
Description
A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand. Executing manipulation of the argument command can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:o:linksys:e1700_firmware:1.0.0.4.003:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- github.com/wudipjq/my_vuln/blob/main/Linksys2/vuln_61/61.mdnvdExploitThird Party Advisory
- github.com/wudipjq/my_vuln/blob/main/Linksys2/vuln_61/61.mdnvdExploitThird Party Advisory
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
- www.linksys.comnvdProduct
News mentions
2- New Dysphoria DDoS botnet spreads to 200k devices worldwideBleepingComputer · Jul 27, 2026
- Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid DisruptionThe Hacker News · Jul 27, 2026