Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 addStaticRoute os command injection
Published Aug 20, 2025
5.3
MEDIUMCVSS 4.0
EPSS 6.71%
Description
A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function addStaticRoute of the file /goform/addStaticRoute. Such manipulation of the argument staticRoute_IP_setting/staticRoute_Netmask_setting/staticRoute_Gateway_setting/staticRoute_Metric_setting/staticRoute_destType_setting leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 1.0.013.001StatusaffectedConstraints-
- Version 1.0.04.001StatusaffectedConstraints-
- Version 1.0.04.002StatusaffectedConstraints-
- Version 1.1.05.003StatusaffectedConstraints-
- Version 1.2.07.001StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linksys | n/a | n/a |
|
Configuration 1
- 1.0.04.001
Configuration 2
- 1.2.07.001
Configuration 3
- 1.0.04.001
Configuration 4
- 1.1.05.003
Configuration 5
- 1.0.04.002
Configuration 6
- 1.0.013.001
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25398 Advisory
- https://github.com/wudipjq/my_vuln/blob/main/Linksys/vuln_11/11.md exploitThird Party Advisory
- https://vuldb.com/?ctiid.320775 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.320775 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.631517 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.linksys.com/ product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25398 | Advisory | |
| https://github.com/wudipjq/my_vuln/blob/main/Linksys/vuln_11/11.md | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.320775 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.320775 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.631517 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.linksys.com/ | product |
Change history (0)
No recorded changes yet.