OS Command Injection Vulnerability in Linksys Wireless Range Extenders
CVE-2025-8827
Key Information:
Badges
What is CVE-2025-8827?
A vulnerability exists in several models of Linksys Wireless Range Extenders, allowing an attacker to exploit the um_inspect_cross_band function via an unvalidated argument in the RP_setBasicAuto endpoint. By manipulating the staticGateway variable, an attacker can execute arbitrary operating system commands. This vulnerability can be exploited remotely, posing a significant threat to users who have not patched their devices. Despite early notification, Linksys has not provided a response regarding this issue.
Affected Version(s)
RE6250 20250801
RE6300 20250801
RE6350 20250801
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved