CVE-2025-44657: Low severity LinkSys EA6350 vulnerability
In Linksys EA6350 V2.1.2, the chrootlocaluser option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In Linksys EA6350 V2.1.2, disable the chroot_local_user option in the dynamically generated vsftpd configuration to prevent unauthorized access to system files and potential privilege escalation/pivoting.
Linksys EA6350 chroot_local_user = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44657?
CVE-2025-44657 is considered a critical vulnerability due to the potential for unauthorized access and privilege escalation.
How do I fix CVE-2025-44657?
To fix CVE-2025-44657, update to the latest firmware version for the Linksys EA6350 router that addresses this vulnerability.
What are the implications of CVE-2025-44657?
CVE-2025-44657 could allow attackers to access sensitive system files and potentially escalate privileges within the network.
Who is affected by CVE-2025-44657?
CVE-2025-44657 affects users of the Linksys EA6350 router running version V2.1.2.
Can CVE-2025-44657 be exploited remotely?
Yes, CVE-2025-44657 can potentially be exploited remotely, allowing attackers to gain unauthorized access without physical access to the device.