CVE-2025-9245
8.8Linksys · RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000
A stack-based buffer overflow vulnerability in Linksys wireless range extenders allows authenticated remote attackers to crash the device or potentially execute arbitrary code via the ssid parameter.
Executive summary
A critical stack-based buffer overflow vulnerability in Linksys range extenders allows authenticated attackers to compromise device stability and potentially execute arbitrary code.
Vulnerability
This is a stack-based buffer overflow (CWE-121) located in the WPSSTAPINEnr function of the /goform/WPSSTAPINEnr endpoint. The vulnerability is triggered when a low-privileged authenticated attacker sends a specially crafted, overly long string to the ssid parameter, which lacks proper bounds checking.
Business impact
Successful exploitation of this vulnerability can lead to a complete denial of service, rendering the affected network infrastructure unusable. Given the potential for arbitrary code execution, an attacker could gain control over the range extender, facilitating lateral movement within the local network or interception of wireless traffic. With a CVSS score of 8.8, this flaw represents a significant risk to network availability and integrity.
Remediation
Immediate Action: Since no official patch is currently available, administrators should restrict access to the web management interface of the affected devices to trusted IP addresses only. Disable the WPS feature if it is not strictly required for network operations.
Proactive Monitoring: Monitor network logs for unusual POST requests directed at the /goform/WPSSTAPINEnr endpoint, particularly those containing excessively large payloads in the ssid field.
Compensating Controls: Deploy a Web Application Firewall (WAF) or implement network access control lists to block unauthorized access to the management interface. Ensure that administrative interfaces are not exposed to the public internet.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up provided by the researcher at the Institute of Information Engineering, Chinese Academy of Sciences.
Analyst recommendation
Given the availability of a public proof-of-concept and the lack of a vendor-supplied patch, this vulnerability poses a credible threat to the integrity and availability of Linksys range extenders. Organizations must immediately isolate these devices from external access and restrict administrative interface entry to known, secure management networks to mitigate the risk of exploitation.
More Linksys CVEs
Sources
Originally found and disclosed by pjqwudi (VulDB User), per the CVE Program record.
- VDB-320776 | Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 WPSSTAPINEnr stack-based overflow Vulnerability database entry
- VDB-320776 | CTI Indicators (IOB, IOC, IOA)
- Submit #631518 | Linksys RE6500、RE6250、RE6300、RE6350、RE7000、RE9000 RE6500(1.0.013.001) RE6250(1.0.04.001) RE6300(1.2.0 Third-party advisory
- Exploit / PoC
- linksys.com