Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26141 | A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function cgiMain of the file /cgi-bin/upload.cgi. Executing manipulation of the argument filename can lead to os command injection. The attack may be performed from a remote location. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. |
Thu, 04 Sep 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linksys re6250 Firmware
Linksys re6300 Firmware Linksys re6350 Firmware Linksys re6500 Firmware Linksys re7000 Firmware Linksys re9000 Firmware |
|
| CPEs | cpe:2.3:h:linksys:re6250:-:*:*:*:*:*:*:* cpe:2.3:h:linksys:re6300:-:*:*:*:*:*:*:* cpe:2.3:h:linksys:re6350:-:*:*:*:*:*:*:* cpe:2.3:h:linksys:re6500:-:*:*:*:*:*:*:* cpe:2.3:h:linksys:re7000:-:*:*:*:*:*:*:* cpe:2.3:h:linksys:re9000:-:*:*:*:*:*:*:* cpe:2.3:o:linksys:re6250_firmware:1.0.04.001:*:*:*:*:*:*:* cpe:2.3:o:linksys:re6300_firmware:1.2.07.001:*:*:*:*:*:*:* cpe:2.3:o:linksys:re6350_firmware:1.0.04.001:*:*:*:*:*:*:* cpe:2.3:o:linksys:re6500_firmware:1.0.013.001:*:*:*:*:*:*:* cpe:2.3:o:linksys:re7000_firmware:1.1.05.003:*:*:*:*:*:*:* cpe:2.3:o:linksys:re9000_firmware:1.0.04.002:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linksys re6250 Firmware
Linksys re6300 Firmware Linksys re6350 Firmware Linksys re6500 Firmware Linksys re7000 Firmware Linksys re9000 Firmware |
Sun, 31 Aug 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linksys
Linksys re6250 Linksys re6300 Linksys re6350 Linksys re6500 Linksys re7000 Linksys re9000 |
|
| Vendors & Products |
Linksys
Linksys re6250 Linksys re6300 Linksys re6350 Linksys re6500 Linksys re7000 Linksys re9000 |
Thu, 28 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function cgiMain of the file /cgi-bin/upload.cgi. Executing manipulation of the argument filename can lead to os command injection. The attack may be performed from a remote location. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 upload.cgi cgiMain os command injection | |
| Weaknesses | CWE-77 CWE-78 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-08-28T18:31:06.309Z
Reserved: 2025-08-28T11:00:44.364Z
Link: CVE-2025-9575
Updated: 2025-08-28T18:30:54.809Z
Status : Analyzed
Published: 2025-08-28T18:15:34.557
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-9575
No data.
OpenCVE Enrichment
Updated: 2025-08-31T08:41:43Z
EUVD