Severity
7.4HIGH
EPSS
0.5%
top 33.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 27

Description

A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the file /goform/setSysAdm. Such manipulation of the argument rm_port leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5linksys/e17001.0.0.4.003
NVDlinksys/e1700_firmware1.0.0.4.003

🔴Vulnerability Details

2
CVEList
Linksys E1700 setSysAdm stack-based overflow2025-08-27
GHSA
GHSA-226f-28jj-g35j: A vulnerability has been found in Linksys E1700 12025-08-27

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS Linksys setSysAdm rm_port Parameter Buffer Overflow Attempt (CVE-2025-9526)2025-08-27
CVE-2025-9526 (HIGH CVSS 7.4) | A vulnerability has been found in L | cvebase.io