HIGH🇵🇱 Wersja polska

CVE-2025-60694

CVSS 7.5v3.1pub. 2025-11-13upd. 2026-07-05

A stack-based buffer overflow exists in the validate_static_route function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function improperly concatenates user-supplied CGI parameters (route_ipaddr_0~3, route_netmask_0~3, route_gateway_0~3) into fixed-size buffers (v6, v10, v14) without proper bounds checking. Remote attackers can exploit this vulnerability via specially crafted HTTP requests to execute arbitrary code or cause denial of service without authentication.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Linksys E1200

    HW
    Linksys
    2
  • Linksys E1200 Firmware

    OS
    Linksys
    2.0.11.001
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDoSMemory
CWE
References

Related vulnerabilities

CVE-2022-38555CRITICAL9.8PL ✓same product

Buffer overflow w Linksys E1200 via ej_get_web_page_name

CVE-2025-60692HIGH8.4same product

A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 route...

CVE-2025-60690HIGH8.8same product

A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 ...

CVE-2025-60691HIGH8.8same product

A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.0...

CVE-2018-3953HIGH7.2same product

Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmwa...