CVE-2025-9362: Linksys RE6250 Firmware

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The impacted element is the function urlFilterManageRule of the file /goform/urlFilterManageRule. Executing manipulation of the argument urlFilterRuleName/scheduleUrl/addURLFilter can lead to stack-based buffer overflow. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

  • Linksys RE6250 Firmware: version 1.0.04.001 only
  • Linksys RE6300 Firmware: version 1.2.07.001 only
  • Linksys RE6350 Firmware: version 1.0.04.001 only
  • Linksys RE6500 Firmware: version 1.0.013.001 only
  • Linksys RE7000 Firmware: version 1.1.05.003 only
  • Linksys RE9000 Firmware: version 1.0.04.002 only

Published 2025-08-23. Last modified 2026-06-17.