Stack-based Buffer Overflow in Linksys E1200 v2 Routers
CVE-2025-60690

8.8HIGH

Key Information:

Vendor

Linksys

Vendor
CVE Published:
13 November 2025

What is CVE-2025-60690?

A stack-based buffer overflow vulnerability exists in the get_merge_ipaddr function of the HTTP daemon on Linksys E1200 v2 routers. This flaw allows remote attackers to exploit the device by sending specially crafted HTTP requests. The function inadequately checks user-supplied CGI parameters, which can lead to the execution of arbitrary code or result in a denial of service. This issue underscores the importance of keeping router firmware updated to mitigate potential threats.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.