CVE-2025-14133: Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so AP_get_wireless_clientlist_setClientsName stack-based overflow
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this vulnerability is the function APgetwirelessclientlistsetClientsName of the file modform.so. Performing manipulation of the argument clientsname0 results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14133?
CVE-2025-14133 is categorized as a high severity vulnerability affecting specific models of Linksys routers.
How do I fix CVE-2025-14133?
To fix CVE-2025-14133, update your Linksys router firmware to the latest available version.
Which Linksys models are affected by CVE-2025-14133?
CVE-2025-14133 affects the Linksys RE6500, RE6250, RE6300, RE6350, RE7000, and RE9000 models.
What is the impact of CVE-2025-14133 on my device?
Exploitation of CVE-2025-14133 could allow unauthorized access to the wireless client list and potentially compromise network security.
Is there a workaround for CVE-2025-14133 if I cannot update the firmware?
Currently, the best practice is to update the firmware; however, limiting external access and disabling unnecessary services may mitigate some risks.