CVE-2025-9528
Linksys E1700 systemCommand os command injection
Description
A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand. Executing manipulation of the argument command can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:UScopeC:LConfidentialityI:LIntegrityA:LAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- DDoS-ботнет Dysphoria заразил более 200 000 устройств по всему мируru-ru·Хакер (xakep.ru)· Incident QiAnXin XLab ddos-botnet
- New Dysphoria DDoS botnet spreads to 200k devices worldwideen-us·BleepingComputer· PoC ddos-botnet
- Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruptionen·The Hacker News· Research ddos-botnet
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-9528 and every CVE in our database. Create a free account — no credit card required.
Create Free Account