Linksys Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Linksys products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
4
In CISA KEV
0
Beyond CISA KEV
4
Sensor Observed
0
Virtual Patch Available
0
Linksys KEVs Added by Year
4 Linksys KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2024-27497
Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file. |
E2000 | High | Not in CISA | 15 Jun 2026 |
|
CVE-2025-34037
Linksys Routers E/WAG/WAP/WES/WET/WRT-Series |
E4200, E3200, E3000, E2500 v1/v2, E2100L v1, E2000, E1550, E1500 v1, E1200 v1, E1000 v1, E900 v1 | High | Not in CISA | 28 May 2026 |
|
CVE-2024-25852
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control... |
RE7000 | High | Not in CISA | 05 Oct 2025 |
|
CVE-2025-8829
Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_setBasicAuto um_red os command injection |
RE6250, RE6300, RE6350, RE6500, RE7000, RE9000 | High | Not in CISA | 11 Aug 2025 |
Common Vulnerability Classes (CWE)
- CWE-284 — Improper Access Control 2
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology