Stack-based Buffer Overflow in Linksys Wireless Routers
CVE-2025-9355
Key Information:
Badges
What is CVE-2025-9355?
A stack-based buffer overflow vulnerability has been detected in multiple Linksys wireless routers, specifically in the scheduleAdd function located in the /goform/scheduleAdd file. By manipulating the argument ruleName, an attacker can potentially exploit this vulnerability remotely. This vulnerability has been disclosed publicly, and attempts to contact the vendor for a fix have gone unanswered. Users of affected models are advised to take precautions to mitigate the risk.
Affected Version(s)
RE6250 1.0.013.001
RE6250 1.0.04.001
RE6250 1.0.04.002
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved