---
id: CVE-2025-52692
title: >-
  Successful exploitation of the vulnerability could allow an attacker with
  local network access to send a specially crafted URL to access certain
  administration functions without login credentials.
summary: >-
  Successful exploitation of the vulnerability could allow an attacker with
  local network access to send a specially crafted URL to access certain
  administration functions without login credentials.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
vendor: linksys
product: e9450-sg_firmware
affected:
  - e9450-sg_firmware = 1.2.00.052
published: '2025-12-19'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-52692'
references:
  - url: 'https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-118/'
    label: 5f57b9bf-260d-4433-bf07-b6a79e9bb7d4
tags:
  - nvd
epss: 0.06364
epssPercentile: 0.93434
ingestedAt: '2026-09-30T23:29:32.506Z'
---

## Overview

Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially crafted URL to access certain administration functions without login credentials.

## Affected

- `e9450-sg_firmware = 1.2.00.052`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
