A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The impacted element is the function RP_pingGatewayByBBS of the file /goform/RP_pingGatewayByBBS. The manipulation of the argument ssidhex results in stack-based buffer overflow. The attack may be performed from a remote location. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
| Software | From | Fixed in |
|---|---|---|
| linksys / re6500_firmware | 1.0.013.001 | 1.0.013.001.x |
| linksys / re6250_firmware | 1.0.04.001 | 1.0.04.001.x |
| linksys / re6300_firmware | 1.2.07.001 | 1.2.07.001.x |
| linksys / re6350_firmware | 1.0.04.001 | 1.0.04.001.x |
| linksys / re7000_firmware | 1.1.05.003 | 1.1.05.003.x |
| linksys / re9000_firmware | 1.0.04.002 | 1.0.04.002.x |