Vulnerability in Linksys Router
19 December 2025
A vulnerability has been discovered in Linksys router. Users and administrators of the affected product version are advised to implement the recommended mitigation measures.
Background
A vulnerability (CVE-2025-52692) has been discovered in Linksys router. The vulnerability has a Common Vulnerability Scoring System (CVSS3.1) score of 8.8 out of 10.
Impact
Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially crafted URL to access certain administration functions without login credentials.
Affected Products
The vulnerability affects Linksys E9450-SG version 1.2.00.052.
Mitigation
As the Linksys E9450-SG has reached End-of-Life status, no firmware update is planned for this issue. Users and administrators of the affected product version are advised to:
Disable remote administration
Restrict router management access to trusted devices on the local network
Avoid enabling Telnet access
Consider upgrading to a model actively supported by Linksys
Credits
CSA would like to express appreciation to Cyber Specialists 2SG Lam Jun Rong and 2SG Javier Koh from the Digital and Intelligence Service (DIS), and Dr Joseph Teo from the Centre for Strategic Infocomm Technologies (CSIT) who worked in partnership to discover the vulnerability.
Additionally, CSA would like to thank Linksys for their collaboration on the coordinated disclosure of the vulnerability.
References
