CVE-2025-9483
8.8Linksys · RE6250, RE6300, RE6350, RE6500, RE7000, RE9000
A stack-based buffer overflow vulnerability in Linksys range extenders allows authenticated remote attackers to execute arbitrary code or crash the device via the singlePortForwardAdd function.
Executive summary
A critical stack-based buffer overflow vulnerability in multiple Linksys range extender models poses a severe risk of remote code execution and persistent service disruption.
Vulnerability
The vulnerability exists within the singlePortForwardAdd function of the /goform/singlePortForwardAdd endpoint. By sending a specially crafted HTTP POST request with excessively long input parameters (ruleName, schedule, or inboundFilter), an authenticated attacker can trigger a stack-based buffer overflow, potentially leading to arbitrary code execution.
Business impact
The exploitation of this vulnerability allows an attacker to gain control over network infrastructure, leading to unauthorized access, potential lateral movement within the local network, and total loss of device availability. Given the CVSS score of 8.8, this flaw represents a high-severity risk that could be leveraged to compromise organizational network integrity.
Remediation
Immediate Action: Since no official patch is currently available, administrators should immediately isolate these devices from untrusted networks and restrict administrative access to authorized management segments only.
Proactive Monitoring: Monitor network traffic for anomalous HTTP POST requests directed at the /goform/singlePortForwardAdd endpoint and review system logs for recurring crashes or unexpected service restarts.
Compensating Controls: Implement strict firewall rules to block unauthorized access to the management interface of these devices, effectively limiting the attack surface to trusted internal users.
Exploitation status
Public Exploit Available: Yes, a published proof of concept exists, as documented in the technical write-up provided by the researcher on GitHub.
Analyst recommendation
Due to the lack of an available vendor patch, the risk of remote code execution remains significant. Organizations should prioritize restricting access to the management interface of affected Linksys devices and monitor for firmware updates from the vendor to remediate this memory corruption flaw as soon as a fix is released.
More Linksys CVEs
Sources
Originally found and disclosed by Bond_yes (VulDB User), per the CVE Program record.
- VDB-321398 | Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 singlePortForwardAdd stack-based overflow Vulnerability database entry
- VDB-321398 | CTI Indicators (IOB, IOC, IOA)
- Submit #634823 | Linksys RE6500、RE6250、RE6300、RE6350、RE7000、RE9000 RE6500(1.0.013.001) RE6250(1.0.04.001) RE6300(1.2.0 Third-party advisory
- Related
- Exploit / PoC
- linksys.com