PT-2025-46880 · Linksys · Linksys E1200 V2
Published
2025-10-09
·
Updated
2025-11-13
·
CVE-2025-60693
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Linksys E1200 v2 routers version E1200 v2.0.11.001 us.tar.gz
Description
A stack-based buffer overflow exists in the
get merge mac function of the httpd binary. The function concatenates up to six user-supplied CGI parameters matching parameter 0 through parameter 5 into a fixed-size buffer (a2) without proper bounds checking, appending colon delimiters during concatenation. Remote attackers can exploit this issue via specially crafted HTTP requests to execute arbitrary code or cause denial of service without authentication.Recommendations
Update to a newer firmware version that addresses this vulnerability. As a temporary workaround, restrict access to the affected CGI parameters (
parameter 0 through parameter 5) to minimize the risk of exploitation.Exploit
Fix
DoS
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linksys E1200 V2