CVE-2025-8832
8.8Linksys · RE6250, RE6300, RE6350, RE6500, RE7000, RE9000
A stack-based buffer overflow in the setDMZ function of various Linksys range extenders allows remote attackers to crash the device or potentially execute arbitrary code via the DMZIPAddress argument.
Executive summary
A critical stack-based buffer overflow vulnerability in multiple Linksys range extender models poses a severe risk of remote service disruption and potential arbitrary code execution.
Vulnerability
This vulnerability is a stack-based buffer overflow occurring in the setDMZ function within the /goform/setDMZ endpoint. An attacker with low-level privileges can supply a malformed DMZIPAddress parameter, which lacks necessary input validation, leading to memory corruption and potential code execution.
Business impact
The ability to remotely trigger a buffer overflow in network infrastructure devices carries significant risk, including persistent denial of service and unauthorized system control. With a CVSS score of 8.8, this flaw represents a high-severity threat that could lead to the complete compromise of network segments if the device is used as a pivot point for further exploitation.
Remediation
Immediate Action: As no vendor patch is currently available, administrators should restrict access to the management interface of the affected devices to trusted internal IP addresses only.
Proactive Monitoring: Monitor device logs and network traffic for unusual POST requests directed at the /goform/setDMZ endpoint or unexpected device reboots.
Compensating Controls: Deploy a Web Application Firewall or an Access Control List to block or sanitize traffic destined for the administrative /goform/ endpoints of these devices.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists via the researcher's write-up on GitHub.
Analyst recommendation
Given the availability of a public proof-of-concept and the lack of a vendor-provided security update, immediate defensive action is required. Organizations should isolate the affected Linksys range extenders from external networks and monitor for signs of unauthorized access until an official firmware patch is released and applied.
More Linksys CVEs
Sources
Originally found and disclosed by pjq123 (VulDB User), per the CVE Program record.
- VDB-319366 | Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 setDMZ stack-based overflow Vulnerability database entry
- VDB-319366 | CTI Indicators (IOB, IOC, IOA)
- Submit #626697 | Linksys RE6500、RE6250、RE6300、RE6350、RE7000、RE9000 RE6500(1.0.013.001) RE6250(1.0.04.001) RE6300(1.2.0 Third-party advisory
- Related
- Exploit / PoC
- linksys.com