CVE-2019-11535: Linksys RE6300 Firmware

Critical severity, CVSS 9.8. EPSS: 5.1% chance of exploitation in the next 30 days.

Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execution. An attacker can access system OS configurations and commands that are not intended for use beyond the web UI.

Affected products

  • Linksys RE6300 Firmware: up to and including 1.2.04.022
  • Linksys RE6400 Firmware: up to and including 1.2.04.022

Published 2019-07-17. Last modified 2026-06-17.