CVE-2025-8826
8.8Linksys · RE6250, RE6300, RE6350, RE6500, RE7000, RE9000
A stack-based buffer overflow in the um_rp_autochannel function of Linksys range extenders allows remote, authenticated attackers to crash the device or potentially execute arbitrary code.
Executive summary
Multiple Linksys range extenders contain a critical stack-based buffer overflow vulnerability that allows remote attackers to compromise device stability and integrity.
Vulnerability
The vulnerability resides in the um_rp_autochannel function within the /goform/RP_setBasicAuto endpoint. By submitting an overly long string to the apcli_AuthMode_2G or apcli_AuthMode_5G parameters, an authenticated attacker can trigger a stack-based buffer overflow, potentially leading to arbitrary code execution.
Business impact
Successful exploitation of this vulnerability can lead to a complete denial of service, rendering the network range extender non-functional. Given the CVSS score of 8.8, the potential for arbitrary code execution poses a severe threat to network security, as attackers could gain control over the internal network infrastructure, leading to unauthorized access to sensitive traffic or further lateral movement within the environment.
Remediation
Immediate Action: As no official patch is currently available, administrators must restrict access to the web management interface of the affected Linksys devices to trusted management subnets only.
Proactive Monitoring: Monitor device logs for unusual POST requests directed at /goform/RP_setBasicAuto, particularly those containing abnormally long strings in the authentication mode parameters.
Compensating Controls: Implement strict firewall rules to prevent unauthorized access to the web administration port (typically port 80/443) of the affected extenders, ensuring that only authorized administrators can reach the management interface.
Exploitation status
Public Exploit Available: Yes, a functional proof-of-concept has been published in a security researcher's GitHub repository.
Analyst recommendation
The severity of this vulnerability, combined with the availability of a public proof-of-concept, necessitates immediate action. Administrators should isolate affected devices from untrusted network segments and monitor for any signs of anomalous traffic targeting the management interface. Until the vendor releases a firmware update, these access restrictions are the most effective defense against potential exploitation.
More Linksys CVEs
Sources
Originally found and disclosed by pjq123 (VulDB User), per the CVE Program record.
- VDB-319360 | Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_setBasicAuto um_rp_autochannel stack-based overflow Vulnerability database entry
- VDB-319360 | CTI Indicators (IOB, IOC, IOA)
- Submit #626691 | Linksys RE6500、RE6250、RE6300、RE6350、RE7000、RE9000 RE6500(1.0.013.001) RE6250(1.0.04.001) RE6300(1.2.0 Third-party advisory
- Related
- Exploit / PoC
- linksys.com