PT-2024-10259 · Linksys · Linksys E8450
Wood1314
·
Published
2024-12-26
·
Updated
2025-01-22
·
CVE-2024-57541
CVSS v3.1
5.5
Medium
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Linksys E8450 version 1.2.00.360516
Description
The issue is related to a buffer overflow vulnerability. The
ipv6 protect status field is copied to the stack without length verification, which can lead to a buffer overflow. This potentially allows attackers to execute arbitrary code on the affected device. The vulnerability is related to the function sub 422eb8 and the use of strncpy without checking the size of the input data.Recommendations
For Linksys E8450 version 1.2.00.360516, as a temporary workaround, consider restricting access to the
ipv6 protect status field until a patch is available. Additionally, avoid using the strncpy function without proper length verification to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linksys E8450