CVE-2025-9362

A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The impacted element is the function urlFilterManageRule of the file /goform/urlFilterManageRule. Executing manipulation of the argument urlFilterRuleName/scheduleUrl/addURLFilter can lead to stack-based buffer overflow. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://github.com/wudipjq/my_vuln/blob/main/Linksys/vuln_30/30.md Exploit Third Party Advisory
https://vuldb.com/?ctiid.321065 Permissions Required
https://vuldb.com/?id.321065 Third Party Advisory VDB Entry
https://vuldb.com/?submit.631534 Third Party Advisory VDB Entry
https://www.linksys.com/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:linksys:re6250_firmware:1.0.04.001:*:*:*:*:*:*:*
cpe:2.3:h:linksys:re6250:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:linksys:re6300_firmware:1.2.07.001:*:*:*:*:*:*:*
cpe:2.3:h:linksys:re6300:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:linksys:re6350_firmware:1.0.04.001:*:*:*:*:*:*:*
cpe:2.3:h:linksys:re6350:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:linksys:re6500_firmware:1.0.013.001:*:*:*:*:*:*:*
cpe:2.3:h:linksys:re6500:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:linksys:re7000_firmware:1.1.05.003:*:*:*:*:*:*:*
cpe:2.3:h:linksys:re7000:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:linksys:re9000_firmware:1.0.04.002:*:*:*:*:*:*:*
cpe:2.3:h:linksys:re9000:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-08-23 14:15

Updated : 2025-09-02 18:18


NVD link : CVE-2025-9362

Mitre link : CVE-2025-9362

CVE.ORG link : CVE-2025-9362


JSON object : View

Products Affected

linksys

  • re6300
  • re9000
  • re6500
  • re9000_firmware
  • re6300_firmware
  • re6250_firmware
  • re7000_firmware
  • re6350_firmware
  • re6350
  • re6500_firmware
  • re6250
  • re7000
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-121

Stack-based Buffer Overflow