Stack-Based Buffer Overflow in Linksys E1200 v2 Routers
CVE-2025-60691
8.8HIGH
What is CVE-2025-60691?
A stack-based buffer overflow vulnerability exists in the httpd binary of Linksys E1200 v2 routers. The flaw occurs in the apply_cgi and block_cgi functions where user-supplied input from the 'url' CGI parameter is copied into stack buffers without proper bounds checking using sprintf. This implementation flaw can lead to a situation where any non-empty input overflows the stack buffers, enabling remote attackers to exploit this vulnerability through specially crafted HTTP requests. Such exploitation could result in arbitrary code execution or denial of service, posing a significant risk to the security and functionality of the affected devices.