ZeroHour

CVE-2025-5447

PoC mass

OS Command Injection in Linksys RE-Series Wi-Fi Range Extenders

CVSS 4.0
5.3 medium
EPSS
32%p98
Published
()
Modified
AI analysis

CVE-2025-5447 is an operating system command injection flaw in the ssid1MACFilter function of the web management interface (/goform/ssid1MACFilter) on several Linksys Wi-Fi range extenders. A remote attacker who can reach the management interface submits crafted values for the apselect_%d and newap_text_%d parameters, which are passed to a shell without adequate sanitization, enabling command execution on the device. The CVSS 4.0 vector indicates low privileges are required (PR:L), so exploitation generally requires access to the management interface, likely with valid login credentials, and the rated impact on confidentiality, integrity and availability is limited. Owners of Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 extenders running the listed firmware versions are affected. A public proof-of-concept has been published (EPSS 32.2%, 98th percentile), there is no confirmed in-the-wild exploitation yet, and the vendor was notified early but did not respond, so no fixed firmware is documented in the available data.

What to do: Check the firmware version on any Linksys RE6500, RE6250, RE6300, RE6350, RE7000 or RE9000 extender and treat the listed builds as vulnerable; because no fixed version is documented, keep the management interface off the internet, restrict access to the web UI (including /goform/ssid1MACFilter) to trusted LAN clients, and use strong admin credentials. Monitor Linksys for a firmware advisory or update and apply it as soon as one becomes available.

Affected
Linksys RE6500 firmware1.0.013.001, 1.0.04.001, 1.0.04.002, 1.1.05.003, 1.2.07.001 (listed for the RE series; per-model mapping not specified)
Linksys RE6250 firmware1.0.013.001, 1.0.04.001, 1.0.04.002, 1.1.05.003, 1.2.07.001 (listed for the RE series; per-model mapping not specified)
Linksys RE6300 firmware1.0.013.001, 1.0.04.001, 1.0.04.002, 1.1.05.003, 1.2.07.001 (listed for the RE series; per-model mapping not specified)
Linksys RE6350 firmware1.0.013.001, 1.0.04.001, 1.0.04.002, 1.1.05.003, 1.2.07.001 (listed for the RE series; per-model mapping not specified)
Linksys RE7000 firmware1.0.013.001, 1.0.04.001, 1.0.04.002, 1.1.05.003, 1.2.07.001 (listed for the RE series; per-model mapping not specified)
Linksys RE9000 firmware1.0.013.001, 1.0.04.001, 1.0.04.002, 1.1.05.003, 1.2.07.001 (listed for the RE series; per-model mapping not specified)
Estimated exposure
masson the order of 1M+ devices sold across the six consumer extender models (share with internet-reachable management interfaces unknown) — Linksys is a leading consumer Wi-Fi vendor and these six long-selling retail range extenders have cumulative unit shipments plausibly exceeding one million, but the data provides no public scan counts, so the number of devices whose admin…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. This vulnerability affects the function ssid1MACFilter of the file /goform/ssid1MACFilter. The manipulation of the argument apselect_%d/newap_text_%d leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Vendors
linksys
Products
re9000 firmware, re6250 firmware, re6300 firmware, re6350 firmware, re7000 firmware, re6500 firmware
Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.