Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

RE6500 — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in RE6500, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses in the Netgear RE6500 wireless range extender, categorized under common vulnerability types such as remote code execution, cross-site scripting, and information disclosure. It serves as a centralized resource for tracking security issues specific to this hardware model, providing a structured view of past and potential threats affecting device stability and user data privacy. The content on this page aggregates vulnerability reports sourced from various security advisories, bug bounty programs, and automated scanning databases. It covers a comprehensive time range, capturing both historical incidents and newly discovered flaws, allowing users and security professionals to assess the ongoing risk profile of the RE6500. By consolidating data from multiple sources, the page aims to provide a holistic understanding of the product's security posture over time, rather than isolating individual events in a vacuum. Visitors to this page can discover critical insights into how specific vulnerabilities impact the RE6500’s functionality and security boundaries. You can track a vendor’s advisories to understand the timeline of disclosure and remediation efforts, gaining clarity on how quickly issues are addressed. Additionally, you can understand a weakness class by observing how different exploitation vectors apply to this specific architecture, such as WiFi management frame handling or firmware update mechanisms. Finally, you can look up a product's vulnerability history to identify recurring patterns or persistent flaws that may require immediate attention or long-term mitigation strategies. This information supports informed decision-making for network administrators and security auditors responsible for maintaining the integrity of IoT deployments.

Vendor: Linksys

CVE ID Title CVSS Severity Published
CVE-2025-14136 Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so stack-based overflow CWE-121 8.8 High 2025-12-06
CVE-2025-14135 Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so AP_get_wired_clientlist_setClientsName stack-based overflow CWE-121 8.8 High 2025-12-06
CVE-2025-14134 Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so stack-based overflow CWE-121 8.8 High 2025-12-06
CVE-2025-14133 Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so AP_get_wireless_clientlist_setClientsName stack-based overflow CWE-121 8.8 High 2025-12-06
CVE-2025-5447 Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 ssid1MACFilter os command injection CWE-78 6.3 Medium 2025-06-02
CVE-2025-5446 Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 RP_checkCredentialsByBBS os command injection CWE-78 6.3 Medium 2025-06-02
CVE-2025-5445 Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 RP_checkFWByBBS os command injection CWE-78 6.3 Medium 2025-06-02
CVE-2025-5444 Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 RP_UpgradeFWByBBS os command injection CWE-78 6.3 Medium 2025-06-02
CVE-2025-5443 Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 wirelessAdvancedHidden os command injection CWE-78 6.3 Medium 2025-06-02
CVE-2025-5442 Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 RP_pingGatewayByBBS os command injection CWE-78 6.3 Medium 2025-06-02
CVE-2025-5441 Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 setDeviceURL os command injection CWE-78 6.3 Medium 2025-06-02
CVE-2025-5440 Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 NTP os command injection CWE-78 6.3 Medium 2025-06-02
CVE-2025-5439 Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 verifyFacebookLike os command injection CWE-78 6.3 Medium 2025-06-02
CVE-2025-5438 Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 WPS command injection CWE-77 6.3 Medium 2025-06-02

All 14 known CVE vulnerabilities affecting RE6500 with full Chinese analysis, references, and POCs where available.