PT-2025-3465 · Linksys · Linksys E8450

Wood1314

·

Published

2025-01-21

·

Updated

2025-01-22

·

CVE-2024-57537

CVSS v3.1

6.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Linksys E8450 version 1.2.00.360516
Description A buffer overflow issue was discovered, where the page field is copied to the stack without length verification. This could allow a remote attacker to execute arbitrary code or cause a denial of service. The vulnerability is related to the sub 422eb8 function in the Wi-Fi router's firmware and involves the strncpy parameter.
Recommendations For Linksys E8450 version 1.2.00.360516, consider disabling the sub 422eb8 function as a temporary workaround until a patch is available. Restrict access to the vulnerable parameter strncpy to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-01578
CVE-2024-57537

Affected Products

Linksys E8450