CVE-2025-9525: Linksys E1700 setWan stack-based overflow
A flaw has been found in Linksys E1700 1.0.0.4.003. Affected by this vulnerability is the function setWan of the file /goform/setWan. This manipulation of the argument DeviceName/lanIp causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9525?
CVE-2025-9525 is rated as a high-severity vulnerability due to its potential for remote exploitation and impact on device stability.
How can I fix CVE-2025-9525?
To mitigate CVE-2025-9525, users should update their Linksys E1700 router to the latest firmware version provided by the manufacturer.
Who is affected by CVE-2025-9525?
CVE-2025-9525 affects users of the Linksys E1700 router running firmware version 1.0.0.4.003.
What types of attacks can exploit CVE-2025-9525?
CVE-2025-9525 can be exploited through remote attacks that trigger a stack-based buffer overflow.
Are there any workarounds for CVE-2025-9525?
As a workaround for CVE-2025-9525, users should limit remote access to their router settings, if possible, until a firmware update is applied.