← All CVEs

CVE-2025-5438

medium · 5.3

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. Affected by this vulnerability is the function WPS of the file /goform/WPS. The manipulation of the argument PIN leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

5.3
CVSS
27.8%
EPSS (exploit prob.)
98th
EPSS percentile
2025-06-02
Published

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Weaknesses

CWE-74CWE-77

Affected products

VendorProductAffected versions
linksysre9000_firmware1.0.04.002
linksysre9000all versions
linksysre6250_firmware1.0.04.001
linksysre6250all versions
linksysre6300_firmware1.2.07.001
linksysre6300all versions
linksysre6350_firmware1.0.04.001
linksysre6350all versions
linksysre7000_firmware1.1.05.003
linksysre7000all versions
linksysre6500_firmware1.0.013.001
linksysre6500all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-5438