CVE-2025-9244: Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 addStaticRoute os command injection
A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function addStaticRoute of the file /goform/addStaticRoute. Such manipulation of the argument staticRouteIPsetting/staticRouteNetmasksetting/staticRouteGatewaysetting/staticRouteMetricsetting/staticRoutedestTypesetting leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9244?
CVE-2025-9244 is classified as a medium severity vulnerability due to potential unauthorized manipulation of the static routing functionality.
How do I fix CVE-2025-9244?
To remediate CVE-2025-9244, users should update their Linksys devices to the latest firmware version that addresses this vulnerability.
What devices are affected by CVE-2025-9244?
CVE-2025-9244 affects Linksys models RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000 running specific firmware versions.
What is the impact of CVE-2025-9244?
The impact of CVE-2025-9244 includes the potential for attackers to manipulate static routes, which could lead to network manipulation and data interception.
Who is responsible for addressing CVE-2025-9244?
It is the responsibility of the device owners and Linksys to ensure that the affected models are patched and updated against CVE-2025-9244.