CVE-2025-9481
8.8Linksys · RE6250, RE6300, RE6350, RE6500, RE7000, RE9000
A stack-based buffer overflow in the Linksys range extender setIpv6 function allows remote authenticated attackers to execute arbitrary code via the tunrd_Prefix parameter.
Executive summary
Multiple Linksys range extenders are vulnerable to a critical buffer overflow that could allow remote code execution by an authenticated attacker.
Vulnerability
The vulnerability exists in the setIpv6 function within the /goform/setIpv6 endpoint. By sending a crafted POST request with an excessively long tunrd_Prefix parameter, an authenticated attacker can trigger a buffer overflow, leading to memory corruption and potential arbitrary code execution.
Business impact
Successful exploitation of this vulnerability allows a remote attacker to gain control over the affected network device. This could lead to a complete compromise of the device, enabling the attacker to intercept network traffic, pivot into the local network, or cause persistent denial of service. With a CVSS score of 8.8, this represents a high-severity risk to network integrity and confidentiality.
Remediation
Immediate Action: There is currently no vendor-provided patch available; administrators should restrict access to the management interface to trusted IP addresses only and disable administrative access from the WAN side immediately.
Proactive Monitoring: Review device access logs for suspicious POST requests directed at the /goform/setIpv6 endpoint, particularly those containing abnormally long string arguments.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) rule to inspect and block excessively long inputs targeting the tunrd_Prefix parameter in administrative forms.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists via the researcher's GitHub write-up referenced in the CVE record.
Analyst recommendation
Given the availability of a public proof-of-concept and the potential for remote code execution, this vulnerability poses a significant risk to the security of the affected network environment. Because no vendor patch has been released, organizations must prioritize network-level segmentation and restrict administrative access to mitigate the threat until an official firmware update is made available.
More Linksys CVEs
Sources
Originally found and disclosed by Bond_yes (VulDB User), per the CVE Program record.
- VDB-321396 | Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 setIpv6 stack-based overflow Vulnerability database entry
- VDB-321396 | CTI Indicators (IOB, IOC, IOA)
- Submit #634819 | Linksys RE6500、RE6250、RE6300、RE6350、RE7000、RE9000 RE6500(1.0.013.001) RE6250(1.0.04.001) RE6300(1.2.0 Third-party advisory
- Related
- Exploit / PoC
- linksys.com