CVE-2025-8833
8.8Linksys · RE6250, RE6300, RE6350, RE6500, RE7000, RE9000
A stack-based buffer overflow in the langSwitchBack function of multiple Linksys range extenders allows remote attackers to trigger a crash or potentially execute arbitrary code via the langSelectionOnly parameter.
Executive summary
A critical stack-based buffer overflow vulnerability in multiple Linksys range extenders allows remote attackers to disrupt service or execute arbitrary code, necessitating immediate containment.
Vulnerability
The vulnerability exists within the langSwitchBack function, located in the /goform/langSwitchBack endpoint, and is triggered by sending a crafted, overly long string to the langSelectionOnly argument. While the CVSS vector indicates PR:L (low privileges required), this flaw allows an authenticated attacker to perform remote code execution via a stack-based buffer overflow.
Business impact
The potential for remote code execution poses a severe risk to network integrity and confidentiality, as an attacker could gain full control over the affected range extender. Given the CVSS score of 8.8, this vulnerability is classified as High severity, which could lead to unauthorized network access, interception of traffic, or permanent denial of service for connected devices.
Remediation
Immediate Action: As no official patch is currently available from the vendor, administrators should immediately restrict access to the management interface of the affected devices to trusted IP addresses only.
Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/langSwitchBack endpoint, particularly those containing abnormally large payloads in the langSelectionOnly field.
Compensating Controls: Deploy a Web Application Firewall or network-level access control list to block unauthorized access to the device administration interface and filter malicious HTTP requests.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the technical write-up provided by the researcher.
Analyst recommendation
Due to the lack of an available vendor patch, the risk of exploitation is elevated. Organizations using these Linksys range extenders must prioritize isolating these devices from the public internet and restricting management access to authorized personnel only. Continued monitoring for firmware updates is essential, and the devices should be updated immediately once the vendor releases a fix.
More Linksys CVEs
Sources
Originally found and disclosed by pjq123 (VulDB User), per the CVE Program record.
- VDB-319367 | Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 langSwitchBack stack-based overflow Vulnerability database entry
- VDB-319367 | CTI Indicators (IOB, IOC, IOA)
- Submit #626698 | Linksys RE6500、RE6250、RE6300、RE6350、RE7000、RE9000 RE6500(1.0.013.001) RE6250(1.0.04.001) RE6300(1.2.0 Third-party advisory
- Related
- Exploit / PoC
- linksys.com