CVE-2025-60694
- EPSS 2.71%
- Veröffentlicht 13.11.2025 17:15:49
- Zuletzt bearbeitet 17.11.2025 19:55:35
A stack-based buffer overflow exists in the validate_static_route function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function improperly concatenates user-supplied CGI parameters (route_ipaddr_0~3, ro...
CVE-2025-60689
- EPSS 0.23%
- Veröffentlicht 13.11.2025 00:00:00
- Zuletzt bearbeitet 19.11.2025 17:30:38
An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl_ant, wl_ssid...
CVE-2025-60690
- EPSS 0.5%
- Veröffentlicht 13.11.2025 00:00:00
- Zuletzt bearbeitet 17.11.2025 19:55:11
A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to four user-supplied CGI parameters matching <parameter>_0~3 i...
CVE-2025-60691
- EPSS 0.5%
- Veröffentlicht 13.11.2025 00:00:00
- Zuletzt bearbeitet 17.11.2025 19:55:22
A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The apply_cgi and block_cgi functions copy user-supplied input from the "url" CGI parameter into stack buffers (v36, v29) usi...
CVE-2025-60692
- EPSS 0.01%
- Veröffentlicht 13.11.2025 00:00:00
- Zuletzt bearbeitet 17.11.2025 19:55:29
A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The functions get_mac_from_ip and get_ip_from_mac use sscanf with overly permissive "%100s" forma...
CVE-2025-60693
- EPSS 1.07%
- Veröffentlicht 13.11.2025 00:00:00
- Zuletzt bearbeitet 17.11.2025 19:55:48
A stack-based buffer overflow exists in the get_merge_mac function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to six user-supplied CGI parameters matching <parameter>_0~5 into ...
CVE-2022-38555
- EPSS 0.66%
- Veröffentlicht 28.08.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:16:39
Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
- EPSS 68.45%
- Veröffentlicht 17.10.2018 02:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:22
Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data passed to and retrieved from NV...
- EPSS 7.96%
- Veröffentlicht 17.10.2018 02:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:22
Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data passed to and retrieved from NV...
- EPSS 1.53%
- Veröffentlicht 17.10.2018 02:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:22
An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04). Specially crafted entries to network configuration information can caus...