CVE-2025-9245: Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 WPSSTAPINEnr stack-based overflow
A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function WPSSTAPINEnr of the file /goform/WPSSTAPINEnr. Performing manipulation of the argument ssid results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9245?
CVE-2025-9245 has been rated as a high severity vulnerability due to its potential impact on network security.
How do I fix CVE-2025-9245?
To fix CVE-2025-9245, update the firmware of affected Linksys products to the latest version provided by the manufacturer.
Which devices are affected by CVE-2025-9245?
CVE-2025-9245 affects Linksys RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000 models.
What type of vulnerability is CVE-2025-9245?
CVE-2025-9245 is a command injection vulnerability affecting the WPSSTAPINEnr function in specified Linksys routers.
Can CVE-2025-9245 be exploited remotely?
Yes, CVE-2025-9245 can be exploited remotely, allowing attackers to manipulate the 'ssid' argument.