CVE-2025-5445: Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 RP_checkFWByBBS os command injection
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this issue is the function RPcheckFWByBBS of the file /goform/RPcheckFWByBBS. The manipulation of the argument type/ch/ssidhex/security/extch/pwd/mode/ip/nm/gw leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5445?
CVE-2025-5445 is classified as a critical vulnerability.
What devices are affected by CVE-2025-5445?
Devices affected by CVE-2025-5445 include Linksys RE6500, RE6250, RE6300, RE6350, RE7000, and RE9000.
How do I fix CVE-2025-5445?
To fix CVE-2025-5445, users should update their devices to the latest firmware version provided by Linksys.
What is the impact of CVE-2025-5445?
CVE-2025-5445 can allow unauthorized access or manipulation of device functions, potentially compromising network security.
When was CVE-2025-5445 disclosed?
The details regarding the exact disclosure date of CVE-2025-5445 have not been specified in available resources.