CVE-2025-9361: Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 ipRangeBlockManageRule stack-based overflow
A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The affected element is the function ipRangeBlockManageRule of the file /goform/ipRangeBlockManageRule. Performing manipulation of the argument ipRangeBlockRuleName/scheduleIp/ipRangeBlockRuleIpAddr results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9361?
CVE-2025-9361 has a high severity rating due to potential remote code execution risks.
How do I fix CVE-2025-9361?
To fix CVE-2025-9361, update the firmware of your Linksys device to the latest version provided by the manufacturer.
Which devices are affected by CVE-2025-9361?
CVE-2025-9361 affects Linksys RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000 models.
What can happen if I am vulnerable to CVE-2025-9361?
If vulnerable to CVE-2025-9361, unauthorized users could gain access to your network settings and potentially execute malicious commands.
When was CVE-2025-9361 reported?
CVE-2025-9361 was reported in 2025, with advisories recommending immediate action for unpatched devices.