cbcvebase.
CVE-2025-9359
published 2025-08-23

CVE-2025-9359: A weakness has been identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue…

high7.4CVSS 4.0
AVNACLATNPRLUINVCHVIHVAHSCNSINSANEPCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
A weakness has been identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function RP_checkCredentialsByBBS of the file /goform/RP_checkCredentialsByBBS. This manipulation of the argument ssidhex/pwd causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
linksysre6250
linksysre6250
linksysre6250
linksysre6250
linksysre6250
linksysre6250_firmware
linksysre6300
linksysre6300
linksysre6300
linksysre6300
linksysre6300
linksysre6300_firmware
linksysre6350
linksysre6350
linksysre6350
linksysre6350
linksysre6350
linksysre6350_firmware
linksysre6500
linksysre6500
linksysre6500
linksysre6500
linksysre6500
linksysre6500_firmware
linksysre7000