CVE-2025-6751: Linksys E8450 HTTP POST Request portal.cgi set_device_language buffer overflow
A vulnerability, which was classified as critical, was found in Linksys E8450 up to 1.2.00.360516. This affects the function setdevicelanguage of the file portal.cgi of the component HTTP POST Request Handler. The manipulation of the argument dutlanguage leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6751?
CVE-2025-6751 is classified as a critical severity vulnerability.
How do I fix CVE-2025-6751?
To mitigate CVE-2025-6751, it is recommended to update the Linksys E8450 firmware to a version higher than 1.2.00.360516.
What component is affected by CVE-2025-6751?
CVE-2025-6751 affects the HTTP POST Request Handler specifically through the function set_device_language in portal.cgi.
What type of vulnerability is CVE-2025-6751?
CVE-2025-6751 is a buffer overflow vulnerability that can be exploited via manipulated arguments.
Who is affected by CVE-2025-6751?
Users of Linksys E8450 devices running firmware version 1.2.00.360516 or lower are affected by CVE-2025-6751.