CVE-2025-8832

high

Description

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This vulnerability affects the function setDMZ of the file /goform/setDMZ. The manipulation of the argument DMZIPAddress leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References

https://www.linksys.com/

https://vuldb.com/?submit.626697

https://vuldb.com/?id.319366

https://vuldb.com/?ctiid.319366

https://github.com/wudipjq/my_vuln/blob/main/Linksys1/vuln_48/48.md#poc

https://github.com/wudipjq/my_vuln/blob/main/Linksys1/vuln_48/48.md

Details

Source: Mitre, NVD

Published: 2025-08-11

Updated: 2025-08-11

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

CVSS v4

Base Score: 8.7

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00082