CVE-2025-9253: Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_doSpecifySiteSurvey stack-based overflow
A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this issue is the function RPdoSpecifySiteSurvey of the file /goform/RPdoSpecifySiteSurvey. The manipulation of the argument ssidhex leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9253?
CVE-2025-9253 is considered a high severity vulnerability that affects multiple Linksys router models.
How do I fix CVE-2025-9253?
To mitigate CVE-2025-9253, it is recommended to update the firmware of affected Linksys models to the latest version available.
Which Linksys models are affected by CVE-2025-9253?
CVE-2025-9253 affects Linksys models RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000.
What kind of vulnerability is CVE-2025-9253?
CVE-2025-9253 is a security vulnerability related to improper input handling in the function RP_doSpecifySiteSurvey.
Can CVE-2025-9253 lead to unauthorized access?
Yes, CVE-2025-9253 could potentially allow attackers to execute unauthorized actions on affected Linksys devices.