CVE-2025-9393: Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 addStaProfile stack-based overflow
A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function addStaProfile of the file /goform/addStaProfile. Performing manipulation of the argument profilename/Ssid/wepkey1/wepkey2/wepkey3/wepkey4/wepkeylength/wepdefaultkey/cipher/passphrase results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9393?
CVE-2025-9393 is classified as a medium severity vulnerability affecting several Linksys router models.
How do I fix CVE-2025-9393?
To fix CVE-2025-9393, you should update your Linksys router firmware to the latest version provided by Linksys.
What products are affected by CVE-2025-9393?
CVE-2025-9393 affects Linksys RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000 routers.
What type of vulnerability is CVE-2025-9393?
CVE-2025-9393 is a remote code execution vulnerability that can be exploited through manipulation of the argument in the addStaProfile function.
Can CVE-2025-9393 be exploited remotely?
Yes, CVE-2025-9393 can be exploited remotely if an attacker manipulates specific arguments related to the vulnerable function.