ZeroHour

CVE-2025-5438

PoC large

Command Injection in WPS Endpoint of Linksys RE-Series Range Extenders

CVSS 4.0
5.3 medium
EPSS
26%p98
Published
()
Modified
AI analysis

CVE-2025-5438 is a command injection flaw (CWE-74/CWE-77) in the WPS handler of six Linksys Wi-Fi range extenders, where attacker-controlled input to the PIN parameter at /goform/WPS is incorporated into an operating-system command without proper validation. The attack can be launched remotely over the network through the device's management interface. An attacker who reaches the vulnerable endpoint can execute arbitrary commands on the extender; the CVSS 4.0 base score of 5.3 (medium) reflects a network-vector attack with low privileges required and low rated confidentiality, integrity and availability impact, although the disclosing source labels it critical. Owners of Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 running the cited firmware versions are affected, and the vendor was contacted early but did not respond. A public proof-of-concept exploit is available on GitHub, EPSS assigns a 26.1% probability of exploitation within 30 days (98th percentile), but the flaw is not yet in CISA KEV and there are no confirmed in-the-wild attacks.

What to do: Check each extender's current firmware version against the affected versions cited above; because the vendor did not respond to the disclosure, no fixed firmware is documented, so treat all listed versions as vulnerable and monitor Linksys support pages for updated releases. Until a patch is available, disable or restrict remote (WAN-side) management of the extender, keep the admin interface limited to the local network, and consider turning off WPS if the model permits it. Prioritize devices whose management interface is reachable from the internet or from guest/untrusted networks.

Affected
Linksys RE6500 firmware1.0.013.001 / 1.0.04.001 / 1.0.04.002 / 1.1.05.003 / 1.2.07.001 (affected firmware versions cited for these models; per-model mapping not specified in the discl
Linksys RE6250 firmware1.0.013.001 / 1.0.04.001 / 1.0.04.002 / 1.1.05.003 / 1.2.07.001 (affected firmware versions cited for these models; per-model mapping not specified in the discl
Linksys RE6300 firmware1.0.013.001 / 1.0.04.001 / 1.0.04.002 / 1.1.05.003 / 1.2.07.001 (affected firmware versions cited for these models; per-model mapping not specified in the discl
Linksys RE6350 firmware1.0.013.001 / 1.0.04.001 / 1.0.04.002 / 1.1.05.003 / 1.2.07.001 (affected firmware versions cited for these models; per-model mapping not specified in the discl
Linksys RE7000 firmware1.0.013.001 / 1.0.04.001 / 1.0.04.002 / 1.1.05.003 / 1.2.07.001 (affected firmware versions cited for these models; per-model mapping not specified in the discl
Linksys RE9000 firmware1.0.013.001 / 1.0.04.001 / 1.0.04.002 / 1.1.05.003 / 1.2.07.001 (affected firmware versions cited for these models; per-model mapping not specified in the discl
Estimated exposure
large≈100,000–1,000,000 consumer devices in the installed base (estimate; devices with the admin interface exposed beyond the LAN are the exploitable subset) — These are six long-selling consumer Wi-Fi range extenders from a major retail brand, so the cumulative installed base is plausibly in the hundreds of thousands, but the disclosure data contains no active-install counts or internet-exposure…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. Affected by this vulnerability is the function WPS of the file /goform/WPS. The manipulation of the argument PIN leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Vendors
linksys
Products
re9000 firmware, re6250 firmware, re6300 firmware, re6350 firmware, re7000 firmware, re6500 firmware
Weakness
CWE-74, CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.