CVE-2025-9575: Linksys RE6250 Firmware

High severity, CVSS 8.8. EPSS: 6.9% chance of exploitation in the next 30 days.

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function cgiMain of the file /cgi-bin/upload.cgi. Executing manipulation of the argument filename can lead to os command injection. The attack may be performed from a remote location. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

  • Linksys RE6250 Firmware: version 1.0.04.001 only
  • Linksys RE6300 Firmware: version 1.2.07.001 only
  • Linksys RE6350 Firmware: version 1.0.04.001 only
  • Linksys RE6500 Firmware: version 1.0.013.001 only
  • Linksys RE7000 Firmware: version 1.1.05.003 only
  • Linksys RE9000 Firmware: version 1.0.04.002 only

Published 2025-08-28. Last modified 2026-06-17.