CVE-2025-9603 carries a CVSS 3.1 base score of 6.3 against Telesquare TLR-2005KSH router firmware version 1.2.4. NVD classifies it as CWE-74/CWE-77 (Injection/Command Injection). VulnCheck’s KEV feed reports the CVE as exploited, dated September 15, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2025-9603 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
Per NVD, the flaw is reachable through a CGI endpoint used for LAN configuration on the router’s web interface. A request parameter representing the device hostname is passed to an internal function without sufficient sanitization, and manipulating that parameter can result in command injection. NVD states the attack can be launched remotely, that the flaw has already been publicly disclosed with working reproduction material, and that Telesquare was contacted about the disclosure but did not respond.
Evidence and confidence
- Medium confidence — the CVSS 6.3 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L), the CWE-74/CWE-77 classification, and the described mechanism all trace to NVD alone in our current ingestion, corroborated by a VulDB catalog entry. The exploitation report traces to VulnCheck KEV alone. - Very high exploitation probability — FIRST’s EPSS model scores this CVE at 0.07575, a 94.2nd percentile score as of our ingestion, among the highest we’ve seen in this batch.
No field is in conflict between our two sources. Our source data does not carry a fixed-version field, and NVD’s own record notes the vendor did not respond to disclosure — a meaningful signal that a fix may not be forthcoming.
Why this matters
An unresponsive vendor combined with public reproduction material and a near-95th-percentile EPSS score is close to a worst-case combination for an internet-facing router flaw: reproduction material is available, exploitation is already confirmed, and there is no indication a patch is coming. Owners of Telesquare TLR-2005KSH routers should treat continued use of internet-exposed management interfaces on this firmware as an active risk and, absent a vendor fix, consider replacing or isolating the affected device from the public internet.
Frequently Asked Questions
What is CVE-2025-9603? A CVSS 6.3 command injection vulnerability (CWE-74/CWE-77) in Telesquare TLR-2005KSH router firmware 1.2.4, reachable through a LAN-configuration CGI endpoint via an unsanitized hostname parameter.
Is CVE-2025-9603 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 15, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Do I need an account to exploit this?
NVD’s CVSS vector indicates low privileges are required (PR:L), meaning some existing, low-level access to the router’s management interface is necessary — though NVD also states the attack can be launched remotely.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Is a fixed version available? Our source data does not carry a fixed-version field. NVD’s own record states the vendor did not respond to the disclosure, so a vendor fix may not currently exist — check with Telesquare directly.
Severity, vector, weakness classification, and the described mechanism sourced from the National Vulnerability Database record for CVE-2025-9603, corroborated by VulDB’s catalog entry. Exploitation status and the September 15, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.