CVE-2025-52692
8.8Linksys · E9450-SG
A vulnerability in the Linksys E9450-SG router allows unauthenticated attackers on the local network to access administrative functions via a crafted URL.
Executive summary
A critical authentication bypass vulnerability in the Linksys E9450-SG router allows unauthenticated local attackers to gain full administrative control over the affected device.
Vulnerability
This is an authentication bypass flaw caused by improper validation of access requests, which permits an unauthenticated attacker with local network access to trigger administrative functions.
Business impact
The vulnerability carries a CVSS score of 8.8, reflecting its high severity and potential for total system compromise. Unauthorized access to administrative functions allows an attacker to modify network configurations, intercept traffic, or completely disable security controls, leading to significant risk of data exfiltration and persistent network compromise.
Remediation
Immediate Action: Contact the vendor or monitor official support channels for the release of a firmware update that addresses this authentication bypass.
Proactive Monitoring: Review administrative access logs for suspicious entries or unauthorized configuration changes originating from local network segments.
Compensating Controls: Restrict access to the router administrative interface by disabling remote management and ensuring that only trusted devices are permitted on the local network segment.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for complete administrative takeover of the device, users should prioritize securing the local network environment immediately. Monitor the Linksys support portal for the official patch and apply it as soon as it becomes available to remediate this authentication flaw.
More Linksys CVEs
Sources
Originally found and disclosed by Lam Jun Rong, Javier Koh, Joseph Teo, per the CVE Program record.