OS Command Injection Vulnerability in Linksys Wi-Fi Range Extenders
CVE-2025-5446
Key Information:
Badges
What is CVE-2025-5446?
A vulnerability exists in several Linksys Wi-Fi range extenders that allows attackers to exploit the RP_checkCredentialsByBBS function through the manipulation of the 'pwd' argument. This vulnerability enables remote command execution, posing significant risks as attackers could gain unauthorized access to the device's operating system. The issue has been publicly disclosed, and affected users are strongly advised to take immediate action as the vendor has not responded adequately to the reported threat.
Affected Version(s)
RE6250 1.0.013.001
RE6250 1.0.04.001
RE6250 1.0.04.002
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved