CVE-2025-14136: Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so stack-based overflow
A security flaw has been discovered in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function RE2000v2RepeatergetwiredclientlistsetClientsName of the file modform.so. The manipulation of the argument clientsname0 results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14136?
CVE-2025-14136 is considered a significant security vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-14136?
To remediate CVE-2025-14136, update the affected Linksys devices to the latest firmware version provided by Linksys.
Which products are affected by CVE-2025-14136?
CVE-2025-14136 affects Linksys models RE6500, RE6250, RE6300, RE6350, RE7000, and RE9000.
What is the impact of CVE-2025-14136?
The impact of CVE-2025-14136 may allow attackers to manipulate client lists and potentially gain unauthorized access to the network.
How can I determine if my device is vulnerable to CVE-2025-14136?
Check the firmware version of your Linksys device against the vulnerable versions listed for CVE-2025-14136 to see if it is affected.