CVE-2025-9392: Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 qosClassifier stack-based overflow
A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function qosClassifier of the file /goform/qosClassifier. Such manipulation of the argument dir/sFromPort/sToPort/dFromPort/dToPort/protocol/layer7/dscp/remarkdscp leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9392?
CVE-2025-9392 is considered a critical security vulnerability affecting specific Linksys router models.
How do I fix CVE-2025-9392?
To fix CVE-2025-9392, update your Linksys router firmware to the latest version provided by Linksys.
Which Linksys models are affected by CVE-2025-9392?
CVE-2025-9392 affects the Linksys models RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000.
What type of impact can CVE-2025-9392 have on affected devices?
CVE-2025-9392 can lead to unauthorized access or manipulation of traffic by exploiting the qosClassifier function.
Is there a workaround for CVE-2025-9392 until I can update my firmware?
Currently, there is no known workaround for CVE-2025-9392 other than applying the firmware update as soon as possible.