CVE-2025-9249: Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 DHCPReserveAddGroup stack-based overflow
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function DHCPReserveAddGroup of the file /goform/DHCPReserveAddGroup. This manipulation of the argument enablegroup/namegroup/ipgroup/macgroup causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9249?
CVE-2025-9249 has been classified with a high severity due to its potential impact on the affected Linksys devices.
How do I fix CVE-2025-9249?
To mitigate CVE-2025-9249, users should update their Linksys devices to the latest firmware version provided by Linksys.
Which Linksys devices are affected by CVE-2025-9249?
CVE-2025-9249 affects multiple Linksys models including RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000.
What function is vulnerable in CVE-2025-9249?
CVE-2025-9249 specifically affects the DHCPReserveAddGroup function in the devices' configuration.
Is there a risk of exploitation with CVE-2025-9249?
Yes, CVE-2025-9249 poses a risk of exploitation which could lead to unauthorized changes in DHCP settings.