Stack-based Buffer Overflow in Linksys Routers
CVE-2025-6752
What is CVE-2025-6752?
A critical vulnerability has been identified in multiple Linksys router models, primarily affecting the function SetDefaultConnectionService within the '/upnp/control/Layer3Forwarding' component. This flaw allows a remote attacker to exploit the argument NewDefaultConnectionService resulting in a stack-based buffer overflow. Given that the exploit has been publicly disclosed, there is an urgent need for affected users to prioritize security measures.
Affected Version(s)
EA7200 20250619
EA7450 20250619
EA7500 20250619
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved