CVE-2025-9246: Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 check_port_conflict stack-based overflow
A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Impacted is the function checkportconflict of the file /goform/checkportconflict. Executing manipulation of the argument singleportrule/portrangerule can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9246?
The severity of CVE-2025-9246 is currently assessed as high due to the potential for remote exploitation.
How do I fix CVE-2025-9246?
To fix CVE-2025-9246, update your Linksys device firmware to the latest version provided by the manufacturer.
What devices are affected by CVE-2025-9246?
CVE-2025-9246 affects Linksys RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000 models.
What impact does CVE-2025-9246 have on my device?
CVE-2025-9246 can allow an attacker to manipulate the function check_port_conflict, potentially leading to unauthorized access.
Is there a workaround for CVE-2025-9246 if I cannot update?
A temporary workaround for CVE-2025-9246 is to disable remote management on the affected Linksys devices until a firmware update can be applied.