PT-2025-35124 · Linksys · Linksys Re6250+5

Bond_Yes

·

Published

2025-08-28

·

Updated

2025-12-27

·

CVE-2025-9575

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linksys RE6250 version 1.0.013.001 Linksys RE6250 version 1.0.04.001 Linksys RE6250 version 1.0.04.002 Linksys RE6250 version 1.1.05.003 Linksys RE6250 version 1.2.07.001 Linksys RE6300 version 1.0.013.001 Linksys RE6300 version 1.0.04.001 Linksys RE6300 version 1.0.04.002 Linksys RE6300 version 1.1.05.003 Linksys RE6300 version 1.2.07.001 Linksys RE6350 version 1.0.013.001 Linksys RE6350 version 1.0.04.001 Linksys RE6350 version 1.0.04.002 Linksys RE6350 version 1.1.05.003 Linksys RE6350 version 1.2.07.001 Linksys RE6500 version 1.0.013.001 Linksys RE6500 version 1.0.04.001 Linksys RE6500 version 1.0.04.002 Linksys RE6500 version 1.1.05.003 Linksys RE6500 version 1.2.07.001 Linksys RE7000 version 1.0.013.001 Linksys RE7000 version 1.0.04.001 Linksys RE7000 version 1.0.04.002 Linksys RE7000 version 1.1.05.003 Linksys RE7000 version 1.2.07.001 Linksys RE9000 version 1.0.013.001 Linksys RE9000 version 1.0.04.001 Linksys RE9000 version 1.0.04.002 Linksys RE9000 version 1.1.05.003 Linksys RE9000 version 1.2.07.001
Description A vulnerability exists in the cgiMain function of the /cgi-bin/upload.cgi file. Manipulation of the filename argument can lead to operating system command injection. This issue can be exploited remotely. The vulnerability has been publicly disclosed.
Recommendations Linksys RE6250 versions prior to 1.0.013.001 Linksys RE6250 versions prior to 1.0.04.001 Linksys RE6250 versions prior to 1.0.04.002 Linksys RE6250 versions prior to 1.1.05.003 Linksys RE6250 versions prior to 1.2.07.001 Linksys RE6300 versions prior to 1.0.013.001 Linksys RE6300 versions prior to 1.0.04.001 Linksys RE6300 versions prior to 1.0.04.002 Linksys RE6300 versions prior to 1.1.05.003 Linksys RE6300 versions prior to 1.2.07.001 Linksys RE6350 versions prior to 1.0.013.001 Linksys RE6350 versions prior to 1.0.04.001 Linksys RE6350 versions prior to 1.0.04.002 Linksys RE6350 versions prior to 1.1.05.003 Linksys RE6350 versions prior to 1.2.07.001 Linksys RE6500 versions prior to 1.0.013.001 Linksys RE6500 versions prior to 1.0.04.001 Linksys RE6500 versions prior to 1.0.04.002 Linksys RE6500 versions prior to 1.1.05.003 Linksys RE6500 versions prior to 1.2.07.001 Linksys RE7000 versions prior to 1.0.013.001 Linksys RE7000 versions prior to 1.0.04.001 Linksys RE7000 versions prior to 1.0.04.002 Linksys RE7000 versions prior to 1.1.05.003 Linksys RE7000 versions prior to 1.2.07.001 Linksys RE9000 versions prior to 1.0.013.001 Linksys RE9000 versions prior to 1.0.04.001 Linksys RE9000 versions prior to 1.0.04.002 Linksys RE9000 versions prior to 1.1.05.003 Linksys RE9000 versions prior to 1.2.07.001 Consider disabling the /cgi-bin/upload.cgi file to prevent exploitation.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-9575

Affected Products

Linksys Re6250
Linksys Re6300
Linksys Re6350
Linksys Ea6500
Linksys Re7000
Linksys Re9000