cve-2025-8829

MEDIUM CVSS 6.3 opencve
Description

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function um_red of the file /goform/RP_setBasicAuto. The manipulation of the argument hname leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Timeline
Published
2025-08-11 04:15 UTC
Last Modified
2026-06-17
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P mitre
3.1 6.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R mitre
3.0 6.3 MEDIUM CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R mitre
4.0 2.1 LOW CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X nvd
3.1 6.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L nvd
4.0 5.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P opencve
3.1 6.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R opencve
3.0 6.3 MEDIUM CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R opencve
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "advisories": [
    {
      "id": "EUVD-2025-24120",
      "source": "euvd",
      "title": "A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function um_red of the file /goform/RP_setBasicAuto. The manipulation of the argument hname leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
      "url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-24120"
    }
  ],
  "cve": "CVE-2025-8829",
  "enrichment": {
    "created": "2025-08-12T07:38:13.277079+00:00",
    "updated": "2025-08-12T07:38:13.277174+00:00",
    "vendors": [
      "linksys",
      "linksys$PRODUCT$re6250",
      "linksys$PRODUCT$re6300",
      "linksys$PRODUCT$re6350",
      "linksys$PRODUCT$re6500",
      "linksys$PRODUCT$re7000",
      "linksys$PRODUCT$re9000"
    ]
  },
  "epss": {
    "score": 0.06814
  },
  "mitre": {
    "cpes": [],
    "created": "2025-08-11T04:02:05.689000+00:00",
    "description": "A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function um_red of the file /goform/RP_setBasicAuto. The manipulation of the argument hname leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
    "metrics": {
      "cvssV2_0": {
        "score": 6.5,
        "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
      },
      "cvssV3_0": {
        "score": 6.3,
        "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
      },
      "cvssV3_1": {
        "score": 6.3,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
      },
      "cvssV4_0": {
        "score": 5.3,
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
      }
    },
    "mitre_repo_path": "cves/2025/8xxx/CVE-2025-8829.json",
    "references": [
      "https://github.com/wudipjq/my_vuln/blob/main/Linksys1/vuln_45/45.md",
      "https://github.com/wudipjq/my_vuln/blob/main/Linksys1/vuln_45/45.md#poc",
      "https://vuldb.com/?ctiid.319363",
      "https://vuldb.com/?id.319363",
      "https://vuldb.com/?submit.626694",
      "https://www.linksys.com/"
    ],
    "title": "Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_setBasicAuto um_red os command injection",
    "updated": "2025-08-12T14:08:05.435000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-77",
      "CWE-78"
    ]
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:h:linksys:re6250:-:*:*:*:*:*:*:*",
      "cpe:2.3:h:linksys:re6300:-:*:*:*:*:*:*:*",
      "cpe:2.3:h:linksys:re6350:-:*:*:*:*:*:*:*",
      "cpe:2.3:h:linksys:re6500:-:*:*:*:*:*:*:*",
      "cpe:2.3:h:linksys:re7000:-:*:*:*:*:*:*:*",
      "cpe:2.3:h:linksys:re9000:-:*:*:*:*:*:*:*",
      "cpe:2.3:o:linksys:re6250_firmware:1.0.04.001:*:*:*:*:*:*:*",
      "cpe:2.3:o:linksys:re6300_firmware:1.2.07.001:*:*:*:*:*:*:*",
      "cpe:2.3:o:linksys:re6350_firmware:1.0.04.001:*:*:*:*:*:*:*",
      "cpe:2.3:o:linksys:re6500_firmware:1.0.013.001:*:*:*:*:*:*:*",
      "cpe:2.3:o:linksys:re7000_firmware:1.1.05.003:*:*:*:*:*:*:*",
      "cpe:2.3:o:linksys:re9000_firmware:1.0.04.002:*:*:*:*:*:*:*"
    ],
    "created": "2025-08-11T04:15:46.643000+00:00",
    "description": "A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function um_red of the file /goform/RP_setBasicAuto. The manipulation of the argument hname leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
    "metrics": {
      "cvssV2_0": {
        "score": 6.5,
        "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
      },
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 6.3,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
      },
      "cvssV4_0": {
        "score": 2.1,
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
      }
    },
    "nvd_repo_path": "2025/CVE-2025-8829.json",
    "references": [
      "https://github.com/wudipjq/my_vuln/blob/main/Linksys1/vuln_45/45.md",
      "https://github.com/wudipjq/my_vuln/blob/main/Linksys1/vuln_45/45.md#poc",
      "https://vuldb.com/?ctiid.319363",
      "https://vuldb.com/?id.319363",
      "https://vuldb.com/?submit.626694",
      "https://www.linksys.com/"
    ],
    "title": null,
    "updated": "2026-06-17T10:07:44.080000+00:00",
    "vendors": [
      "linksys",
      "linksys$PRODUCT$re6250",
      "linksys$PRODUCT$re6250_firmware",
      "linksys$PRODUCT$re6300",
      "linksys$PRODUCT$re6300_firmware",
      "linksys$PRODUCT$re6350",
      "linksys$PRODUCT$re6350_firmware",
      "linksys$PRODUCT$re6500",
      "linksys$PRODUCT$re6500_firmware",
      "linksys$PRODUCT$re7000",
      "linksys$PRODUCT$re7000_firmware",
      "linksys$PRODUCT$re9000",
      "linksys$PRODUCT$re9000_firmware"
    ],
    "weaknesses": [
      "CWE-77",
      "CWE-78"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2025-08-11T04:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function um_red of the file /goform/RP_setBasicAuto. The manipulation of the argument hname leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "new": "Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_setBasicAuto um_red os command injection",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-77",
                "CWE-78"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "https://github.com/wudipjq/my_vuln/blob/main/Linksys1/vuln_45/45.md",
                "https://github.com/wudipjq/my_vuln/blob/main/Linksys1/vuln_45/45.md#poc",
                "https://vuldb.com/?ctiid.319363",
                "https://vuldb.com/?id.319363",
                "https://vuldb.com/?submit.626694",
                "https://www.linksys.com/"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV2_0": {
                  "score": 6.5,
                  "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
                },
                "cvssV3_0": {
                  "score": 6.3,
                  "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
                },
                "cvssV3_1": {
                  "score": 6.3,
                  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
                },
                "cvssV4_0": {
                  "score": 5.3,
                  "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "91958859-130d-419b-a3ce-4c61c002bedf"
      },
      {
        "created": "2025-08-12T07:45:00+00:00",
        "data": [
          {
            "details": [
              "linksys",
              "linksys$PRODUCT$re6250",
              "linksys$PRODUCT$re6300",
              "linksys$PRODUCT$re6350",
              "linksys$PRODUCT$re6500",
              "linksys$PRODUCT$re7000",
              "linksys$PRODUCT$re9000"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "linksys",
                "linksys$PRODUCT$re6250",
                "linksys$PRODUCT$re6300",
                "linksys$PRODUCT$re6350",
                "linksys$PRODUCT$re6500",
                "linksys$PRODUCT$re7000",
                "linksys$PRODUCT$re9000"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "3c9bd502-51c3-46d1-9767-6878aaa1672b"
      },
      {
        "created": "2025-08-12T14:15:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "poc",
                    "Technical Impact": "partial"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "7311157d-e8d8-4810-86e7-bddb50e60086"
      },
      {
        "created": "2025-09-04T18:45:00+00:00",
        "data": [
          {
            "details": [
              "linksys$PRODUCT$re6250_firmware",
              "linksys$PRODUCT$re6300_firmware",
              "linksys$PRODUCT$re6350_firmware",
              "linksys$PRODUCT$re6500_firmware",
              "linksys$PRODUCT$re7000_firmware",
              "linksys$PRODUCT$re9000_firmware"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:h:linksys:re6250:-:*:*:*:*:*:*:*",
                "cpe:2.3:h:linksys:re6300:-:*:*:*:*:*:*:*",
                "cpe:2.3:h:linksys:re6350:-:*:*:*:*:*:*:*",
                "cpe:2.3:h:linksys:re6500:-:*:*:*:*:*:*:*",
                "cpe:2.3:h:linksys:re7000:-:*:*:*:*:*:*:*",
                "cpe:2.3:h:linksys:re9000:-:*:*:*:*:*:*:*",
                "cpe:2.3:o:linksys:re6250_firmware:1.0.04.001:*:*:*:*:*:*:*",
                "cpe:2.3:o:linksys:re6300_firmware:1.2.07.001:*:*:*:*:*:*:*",
                "cpe:2.3:o:linksys:re6350_firmware:1.0.04.001:*:*:*:*:*:*:*",
                "cpe:2.3:o:linksys:re6500_firmware:1.0.013.001:*:*:*:*:*:*:*",
                "cpe:2.3:o:linksys:re7000_firmware:1.1.05.003:*:*:*:*:*:*:*",
                "cpe:2.3:o:linksys:re9000_firmware:1.0.04.002:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "linksys$PRODUCT$re6250_firmware",
                "linksys$PRODUCT$re6300_firmware",
                "linksys$PRODUCT$re6350_firmware",
                "linksys$PRODUCT$re6500_firmware",
                "linksys$PRODUCT$re7000_firmware",
                "linksys$PRODUCT$re9000_firmware"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "054e400f-a266-4075-a4ee-d5189ba5f351"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:h:linksys:re6250:-:*:*:*:*:*:*:*",
        "cpe:2.3:h:linksys:re6300:-:*:*:*:*:*:*:*",
        "cpe:2.3:h:linksys:re6350:-:*:*:*:*:*:*:*",
        "cpe:2.3:h:linksys:re6500:-:*:*:*:*:*:*:*",
        "cpe:2.3:h:linksys:re7000:-:*:*:*:*:*:*:*",
        "cpe:2.3:h:linksys:re9000:-:*:*:*:*:*:*:*",
        "cpe:2.3:o:linksys:re6250_firmware:1.0.04.001:*:*:*:*:*:*:*",
        "cpe:2.3:o:linksys:re6300_firmware:1.2.07.001:*:*:*:*:*:*:*",
        "cpe:2.3:o:linksys:re6350_firmware:1.0.04.001:*:*:*:*:*:*:*",
        "cpe:2.3:o:linksys:re6500_firmware:1.0.013.001:*:*:*:*:*:*:*",
        "cpe:2.3:o:linksys:re7000_firmware:1.1.05.003:*:*:*:*:*:*:*",
        "cpe:2.3:o:linksys:re9000_firmware:1.0.04.002:*:*:*:*:*:*:*"
      ],
      "providers": [
        "nvd"
      ]
    },
    "created": {
      "data": "2025-08-11T04:02:05.689000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function um_red of the file /goform/RP_setBasicAuto. The manipulation of the argument hname leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {
          "score": 6.5,
          "vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
        },
        "provider": "mitre"
      },
      "cvssV3_0": {
        "data": {
          "score": 6.3,
          "vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        "provider": "mitre"
      },
      "cvssV3_1": {
        "data": {
          "score": 6.3,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {
          "score": 5.3,
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
        },
        "provider": "mitre"
      },
      "epss": {
        "data": {
          "score": 0.06814
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "poc",
            "Technical Impact": "partial"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://github.com/wudipjq/my_vuln/blob/main/Linksys1/vuln_45/45.md",
        "https://github.com/wudipjq/my_vuln/blob/main/Linksys1/vuln_45/45.md#poc",
        "https://vuldb.com/?ctiid.319363",
        "https://vuldb.com/?id.319363",
        "https://vuldb.com/?submit.626694",
        "https://www.linksys.com/"
      ],
      "providers": [
        "mitre",
        "nvd",
        "vulnrichment"
      ]
    },
    "title": {
      "data": "Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_setBasicAuto um_red os command injection",
      "provider": "mitre"
    },
    "updated": {
      "data": "2025-09-04T18:36:17.483000+00:00",
      "provider": "nvd"
    },
    "vendors": {
      "data": [
        "linksys",
        "linksys$PRODUCT$re6250",
        "linksys$PRODUCT$re6250_firmware",
        "linksys$PRODUCT$re6300",
        "linksys$PRODUCT$re6300_firmware",
        "linksys$PRODUCT$re6350",
        "linksys$PRODUCT$re6350_firmware",
        "linksys$PRODUCT$re6500",
        "linksys$PRODUCT$re6500_firmware",
        "linksys$PRODUCT$re7000",
        "linksys$PRODUCT$re7000_firmware",
        "linksys$PRODUCT$re9000",
        "linksys$PRODUCT$re9000_firmware"
      ],
      "providers": [
        "nvd",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-77",
        "CWE-78"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2025-08-11T04:02:05.689000+00:00",
    "description": "A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function um_red of the file /goform/RP_setBasicAuto. The manipulation of the argument hname leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "poc",
          "Technical Impact": "partial"
        },
        "version": "2.0.3"
      }
    },
    "references": [
      "https://github.com/wudipjq/my_vuln/blob/main/Linksys1/vuln_45/45.md",
      "https://github.com/wudipjq/my_vuln/blob/main/Linksys1/vuln_45/45.md#poc"
    ],
    "title": "Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_setBasicAuto um_red os command injection",
    "updated": "2025-08-12T14:07:49.112000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2025/8xxx/CVE-2025-8829.json",
    "weaknesses": []
  }
}
Enrichment data
View JSON API Download JSON