CVE Details
Basic Information
| Title | Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 wirelessAdvancedHidden os command injection |
|---|---|
| Type | cve |
| Published | 2025-06-02T11:31:04.438Z |
| Last Seen |
Product Information
| Vendor | Linksys |
|---|---|
| Product | RE6500 |
| Version | 1.0.013.001 |
CVSS Information
| Base Score | 5.3 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A critical vulnerability in Linksys RE6500, RE6250, RE6300, RE6350, RE7000, and RE9000 allows remote attackers to execute arbitrary OS commands via the ExtChSelector/24GSelector/5GSelector parameters in the wirelessAdvancedHidden function. The exploit is publicly available, and the vendor has not responded to the disclosure. |
|---|---|
| AI Severity | Critical |
| Vendor | Linksys |
| Product | RE6500, RE6250, RE6300, RE6350, RE7000, RE9000 |
| Affected Version | 1.0.013.001, 1.0.04.001, 1.0.04.002, 1.1.05.003, 1.2.07.001 |
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-78, CWE-77 |
| Bulletin Family | |
| Source Data | Linksys RE6500 1.0.013.001 Linksys RE6500 1.0.04.001 Linksys RE6500 1.0.04.002 Linksys RE6500 1.1.05.003 Linksys RE6500 1.2.07.001 Linksys RE6250 1.0.013.001 Linksys RE6250 1.0.04.001 Linksys RE6250 1.0.04.002 Linksys RE6250 1.1.05.003 Linksys RE6250 1.2.07.001 Linksys RE6300 1.0.013.001 Linksys RE6300 1.0.04.001 Linksys RE6300 1.0.04.002 Linksys RE6300 1.1.05.003 Linksys RE6300 1.2.07.001 Linksys RE6350 1.0.013.001 Linksys RE6350 1.0.04.001 Linksys RE6350 1.0.04.002 Linksys RE6350 1.1.05.003 Linksys RE6350 1.2.07.001 Linksys RE7000 1.0.013.001 Linksys RE7000 1.0.04.001 Linksys RE7000 1.0.04.002 Linksys RE7000 1.1.05.003 Linksys RE7000 1.2.07.001 Linksys RE9000 1.0.013.001 Linksys RE9000 1.0.04.001 Linksys RE9000 1.0.04.002 Linksys RE9000 1.1.05.003 Linksys RE9000 1.2.07.001 |
Source Information
Description
A vulnerability, which was classified as critical, was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected is the function wirelessAdvancedHidden of the file /goform/wirelessAdvancedHidden. The manipulation of the argument ExtChSelector/24GSelector/5GSelector leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score Summary
Base Score: 5.3 (MEDIUM)