← voltar
CVE-2025-60693

CVE-2025-60693

CVSS 6.5 MEDIUMEPSS 0.8%CWE-121
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 6.5EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
13 nov 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A stack-based buffer overflow exists in the get_merge_mac function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to six user-supplied CGI parameters matching <parameter>_0~5 into a fixed-size buffer (a2) without proper bounds checking, appending colon delimiters during concatenation. Remote attackers can exploit this vulnerability via specially crafted HTTP requests to execute arbitrary code or cause denial of service without authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Produtos afetados
n/a · n/a