Stack-Based Buffer Overflow in Linksys E1200 v2 Routers
CVE-2025-60691
8.8HIGH
What is CVE-2025-60691?
A stack-based buffer overflow vulnerability exists in the httpd binary of Linksys E1200 v2 routers. The flaw occurs in the apply_cgi and block_cgi functions where user-supplied input from the 'url' CGI parameter is copied into stack buffers without proper bounds checking using sprintf. This implementation flaw can lead to a situation where any non-empty input overflows the stack buffers, enabling remote attackers to exploit this vulnerability through specially crafted HTTP requests. Such exploitation could result in arbitrary code execution or denial of service, posing a significant risk to the security and functionality of the affected devices.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved