8.8

CVE-2025-5438

Exploit

Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 WPS command injection

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. Affected by this vulnerability is the function WPS of the file /goform/WPS. The manipulation of the argument PIN leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linksys ≫ Re9000 Firmware Version 1.0.04.002
   Linksys ≫ Re9000 Version -
Linksys ≫ Re6250 Firmware Version 1.0.04.001
   Linksys ≫ Re6250 Version -
Linksys ≫ Re6300 Firmware Version 1.2.07.001
   Linksys ≫ Re6300 Version -
Linksys ≫ Re6350 Firmware Version 1.0.04.001
   Linksys ≫ Re6350 Version -
Linksys ≫ Re7000 Firmware Version 1.1.05.003
   Linksys ≫ Re7000 Version -
Linksys ≫ Re6500 Firmware Version 1.0.013.001
   Linksys ≫ Re6500 Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 26.5% 0.978
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cna@vuldb.com 5.3 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cna@vuldb.com 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cna@vuldb.com 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

https://www.linksys.com/
Product
https://vuldb.com/?id.310777
Third Party Advisory
VDB Entry
https://vuldb.com/?ctiid.310777
VDB Entry
Permissions Required
https://vuldb.com/?submit.584360
Third Party Advisory
VDB Entry
https://github.com/wudipjq/my_vuln/blob/main/Linksys/vuln_1/1.md
Exploit