CVE-2025-9482: Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 portRangeForwardAdd stack-based overflow
A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This impacts the function portRangeForwardAdd of the file /goform/portRangeForwardAdd. The manipulation of the argument ruleName/schedule/inboundFilter/TCPPorts/UDPPorts results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9482?
CVE-2025-9482 is considered a high-severity vulnerability due to its potential impact on network security.
How do I fix CVE-2025-9482?
To fix CVE-2025-9482, update your Linksys device firmware to the latest version provided by Linksys.
Which devices are affected by CVE-2025-9482?
CVE-2025-9482 affects Linksys RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000 routers.
What is the impact of CVE-2025-9482 on my Linksys router?
The impact of CVE-2025-9482 allows for unauthorized access and manipulation of port forwarding rules on affected Linksys routers.
Is there a workaround for CVE-2025-9482 if I cannot update immediately?
As a temporary workaround for CVE-2025-9482, disable remote management and restrict access to the router settings.