CVE-2025-14134: Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so stack-based overflow
A vulnerability was determined in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this issue is the function RE2000v2RepeatergetwirelessclientlistsetClientsName of the file modform.so. Executing manipulation of the argument clientsname0 can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14134?
CVE-2025-14134 has been classified as a medium-severity vulnerability affecting multiple Linksys router models.
How do I fix CVE-2025-14134?
To mitigate CVE-2025-14134, update your Linksys RE6500, RE6250, RE6300, RE6350, RE7000, or RE9000 routers to the latest firmware version provided by Linksys.
Who is affected by CVE-2025-14134?
CVE-2025-14134 affects users of Linksys RE6500, RE6250, RE6300, RE6350, RE7000, and RE9000 routers running specified vulnerable firmware versions.
What is the primary impact of CVE-2025-14134?
The primary impact of CVE-2025-14134 is the potential for unauthorized access to the device and manipulation of wireless client settings.
Is there a workaround for CVE-2025-14134?
A recommended workaround for CVE-2025-14134 is to disable remote management and change default access credentials on the affected Linksys routers.