← All CVEs

CVE-2025-5446

medium · 5.3

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been classified as critical. This affects the function RP_checkCredentialsByBBS of the file /goform/RP_checkCredentialsByBBS. The manipulation of the argument pwd leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

5.3
CVSS
15.0%
EPSS (exploit prob.)
97th
EPSS percentile
2025-06-02
Published

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Weaknesses

CWE-77CWE-78

Affected products

VendorProductAffected versions
linksysre9000_firmware1.0.04.002
linksysre9000all versions
linksysre6250_firmware1.0.04.001
linksysre6250all versions
linksysre6300_firmware1.2.07.001
linksysre6300all versions
linksysre6350_firmware1.0.04.001
linksysre6350all versions
linksysre7000_firmware1.1.05.003
linksysre7000all versions
linksysre6500_firmware1.0.013.001
linksysre6500all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-5446