A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function cgiMain of the file /cgi-bin/upload.cgi. Executing manipulation of the argument filename can lead to os command injection. The attack may be performed from a remote location. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
2025-08-28T18:15:34.557
2025-09-04T18:32:04.087
Analyzed
CVSSv3.1: 6.3 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? | 
|---|---|---|---|---|
| Operating System | linksys | re6250_firmware | 1.0.04.001 | Yes | 
| Hardware | linksys | re6250 | - | No | 
| Operating System | linksys | re6300_firmware | 1.2.07.001 | Yes | 
| Hardware | linksys | re6300 | - | No | 
| Operating System | linksys | re6350_firmware | 1.0.04.001 | Yes | 
| Hardware | linksys | re6350 | - | No | 
| Operating System | linksys | re7000_firmware | 1.1.05.003 | Yes | 
| Hardware | linksys | re7000 | - | No | 
| Operating System | linksys | re9000_firmware | 1.0.04.002 | Yes | 
| Hardware | linksys | re9000 | - | No | 
| Operating System | linksys | re6500_firmware | 1.0.013.001 | Yes | 
| Hardware | linksys | re6500 | - | No |