PT-2025-32497 · Linksys · Linksys Re6250+5

Pjqwudi

·

Published

2025-08-01

·

Updated

2025-09-04

·

CVE-2025-8820

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 versions up to 20250801
Description: A vulnerability exists due to a stack-based buffer overflow in the wirelessBasic function within the /goform/wirelessBasic file. The vulnerability is triggered by manipulating the submit SSID1 argument, allowing for remote exploitation. The exploit has been publicly disclosed.
Recommendations: Versions up to 20250801: Address the buffer overflow in the wirelessBasic function by validating the submit SSID1 argument to prevent excessive input length.

Exploit

Fix

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-09662
CVE-2025-8820

Affected Products

Linksys Re6250
Linksys Re6300
Linksys Re6350
Linksys Ea6500
Linksys Re7000
Linksys Re9000