Stack-Based Buffer Overflow in Linksys Wireless Range Extenders
CVE-2025-9253
Key Information:
Badges
What is CVE-2025-9253?
A notable stack-based buffer overflow vulnerability exists in multiple Linksys wireless range extenders, specifically in the RP_doSpecifySiteSurvey function. An attacker can exploit this issue remotely by manipulating the ssidhex argument, potentially allowing for unauthorized access or control over the device. The impacted devices include popular models like RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000 across various firmware versions. Despite early notification to the vendor, no response was received, raising concerns about the potential risks to users.
Affected Version(s)
RE6250 1.0.013.001
RE6250 1.0.04.001
RE6250 1.0.04.002
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved