PT-2025-46869 · Linksys · Linksys E7350 Router

Published

2025-10-09

·

Updated

2025-11-13

·

CVE-2025-60695

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Linksys E7350 Router versions 1.1.00.032
Description A stack-based buffer overflow exists in the mtk dut binary. The sub 4045A8 function reads up to 256 bytes from /sys/class/net/%s/address into a local buffer and copies it into a caller-provided buffer a1 using strcpy without boundary checks. The a1 buffer is often allocated with smaller sizes (20-32 bytes), allowing attackers controlling the contents of /sys/class/net/%s/address to trigger buffer overflows. This can lead to memory corruption, denial of service, or potential arbitrary code execution.
Recommendations Update Linksys E7350 Router firmware to a version newer than 1.1.00.032.

Exploit

Fix

DoS

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-14914
CVE-2025-60695

Affected Products

Linksys E7350 Router