CVE-2025-9247: Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 setVlan stack-based overflow
A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The affected element is the function setVlan of the file /goform/setVlan. The manipulation of the argument vlanset leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9247?
CVE-2025-9247 is classified as a significant vulnerability affecting several Linksys router models.
How do I fix CVE-2025-9247?
To fix CVE-2025-9247, update your Linksys router firmware to the latest version provided by the manufacturer.
Which devices are affected by CVE-2025-9247?
CVE-2025-9247 affects Linksys RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000 models.
What type of vulnerability is CVE-2025-9247?
CVE-2025-9247 is a stack-based buffer overflow vulnerability.
What potential impact does CVE-2025-9247 have?
Exploitation of CVE-2025-9247 could allow an attacker to execute arbitrary code on the affected devices.