CVE-2025-52692

HIGH

Linksys E9450-SG Firmware - Unauthenticated Access to Administration Functions via Crafted URL

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-52692. PoCs published by yt2w.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2025-52692, an authentication bypass vulnerability in Linksys E9450-SG routers. The exploit enables a hidden Telnet server with root access by sending an unauthenticated HTTP GET request to a specific endpoint.

Description

Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially crafted URL to access certain administration functions without login credentials.

Exploits (1)

nomisec WORKING POC
by yt2w · poc
https://github.com/yt2w/CVE-2025-52692

This repository contains a functional exploit for CVE-2025-52692, an authentication bypass vulnerability in Linksys E9450-SG routers. The exploit enables a hidden Telnet server with root access by sending an unauthenticated HTTP GET request to a specific endpoint.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Linksys E9450-SG firmware 1.2.00.052
No auth needed
Prerequisites: Network access to the router's LAN interface
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0562
EPSS Percentile 91.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-306
Status published
Products (1)
linksys/e9450-sg_firmware 1.2.00.052
Published Dec 19, 2025
Tracked Since Feb 18, 2026