CVE-2025-9251: Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 sta_wps_pin stack-based overflow
A security flaw has been discovered in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected is the function stawpspin of the file /goform/stawpspin. Performing manipulation of the argument Ssid results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9251?
CVE-2025-9251 has been rated as a high severity vulnerability due to potential unauthorized access risks.
How do I fix CVE-2025-9251?
To fix CVE-2025-9251, ensure your Linksys RE6250, RE6300, RE6350, RE6500, RE7000, or RE9000 routers are updated to the latest firmware version provided by Linksys.
Which devices are affected by CVE-2025-9251?
CVE-2025-9251 affects the Linksys RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000 models.
What specific component is vulnerable in CVE-2025-9251?
The vulnerable component in CVE-2025-9251 is the function sta_wps_pin in the file /goform/sta_wps_pin.
What can attackers achieve through CVE-2025-9251?
Attackers exploiting CVE-2025-9251 may manipulate the Ssid argument to gain unauthorized access to the router.