A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function cgiMain of the file /cgi-bin/upload.cgi. Executing manipulation of the argument filename can lead to os command injection. The attack may be performed from a remote location. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
References
| Link | Resource |
|---|---|
| https://github.com/wudipjq/my_vuln/blob/main/Linksys/vuln_13/13.md | Exploit Third Party Advisory |
| https://github.com/wudipjq/my_vuln/blob/main/Linksys/vuln_13/13.md#poc | Exploit Third Party Advisory |
| https://vuldb.com/?ctiid.321689 | Permissions Required VDB Entry |
| https://vuldb.com/?id.321689 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.634840 | Third Party Advisory VDB Entry |
| https://www.linksys.com/ | Product |
| https://github.com/wudipjq/my_vuln/blob/main/Linksys/vuln_13/13.md | Exploit Third Party Advisory |
| https://github.com/wudipjq/my_vuln/blob/main/Linksys/vuln_13/13.md#poc | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
History
No history.
Information
Published : 2025-08-28 18:15
Updated : 2025-09-04 18:32
NVD link : CVE-2025-9575
Mitre link : CVE-2025-9575
CVE.ORG link : CVE-2025-9575
JSON object : View
Products Affected
linksys
- re6300
- re9000
- re6500
- re9000_firmware
- re6300_firmware
- re6250_firmware
- re7000_firmware
- re6350_firmware
- re6350
- re6500_firmware
- re6250
- re7000
