OS Command Injection Vulnerability in Linksys Routers
CVE-2025-8830
Key Information:
Badges
What is CVE-2025-8830?
An OS command injection vulnerability has been identified in the Linksys RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000 routers up to firmware version 20250801. The vulnerability exists in the function sub_3517C found in the /goform/setWan file, where improper handling of the Hostname argument can be exploited. This flaw allows remote attackers to execute arbitrary operating system commands by crafting malicious input. Despite early notification to Linksys, the company has not responded to the disclosure of this significant security risk.
Affected Version(s)
RE6250 20250801
RE6300 20250801
RE6350 20250801
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved