CRITICAL🇵🇱 Wersja polska

CVE-2025-44654

CVSS 9.8v3.1pub. 2025-07-21upd. 2026-07-05

In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

🤖 AI Analysis
How it works

The FTP service (vsftpd) on the Linksys E2500 device is configured with the chroot_local_user option enabled, however this configuration is flawed or improperly implemented. This results in a local FTP user not being properly isolated in their home directory and being able to access a broader file system of the device. An attacker can exploit this vulnerability to escalate privileges or move through the internal network from the level of a compromised device.

Impact

An attacker can gain unauthorized access to system files on the device, perform privilege escalation, and also use the compromised device as a pivot point for attacks on the internal network.

Mitigation & patch

Apply patches available from the manufacturer according to the references. As a temporary measure, it is recommended to disable the FTP service on the device and restrict access to the management interface exclusively to trusted hosts on the local network.

Who is affected

Linksys E2500 with firmware version 3.0.04.002

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Linksys E2500

    HW
    Linksys
    all versions
  • Linksys E2500 Firmware

    OS
    Linksys
    3.0.04.002
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2024-40495HIGH8.0same product

A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to...

CVE-2018-3953HIGH7.2same product

Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmwa...

CVE-2018-3954HIGH7.2same product

Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmwa...

CVE-2018-3955HIGH7.2same product

An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200...

CVE-2025-29228CRITICAL9.8PL ✓same vendor

Command injection w Linksys E5600 — parametr mc.ip funkcji macClone