Remote Code Execution Vulnerability in Linksys Routers
CVE-2025-8821

5.3MEDIUM

Key Information:

Vendor

Linksys

Status
Vendor
CVE Published:
11 August 2025

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2025-8821?

A security flaw was found in multiple Linksys router models, where the 'RP_setBasic' function becomes susceptible to os command injection through improper handling of user inputs. This vulnerability enables remote adversaries to inject malicious commands into the system, potentially leading to unauthorized system access and manipulation. Although the vendor was alerted about this critical issue, no response has been received. It is imperative for users of the affected models to take defensive actions promptly.

Affected Version(s)

RE6250 20250801

RE6300 20250801

RE6350 20250801

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

.