CVE-2025-9526: Linksys E1700 setSysAdm stack-based overflow
A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the file /goform/setSysAdm. Such manipulation of the argument rmport leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9526?
CVE-2025-9526 is considered a critical vulnerability due to its potential for remote exploitation and causing stack-based buffer overflow.
How do I fix CVE-2025-9526?
To fix CVE-2025-9526, it is recommended to update the Linksys E1700 firmware to the latest version provided by the manufacturer.
What system is affected by CVE-2025-9526?
CVE-2025-9526 affects the Linksys E1700 router running version 1.0.0.4.003.
What kind of attack can exploit CVE-2025-9526?
CVE-2025-9526 can be exploited through a remote attack that manipulates the rm_port argument, leading to a stack-based buffer overflow.
Is remote access needed to exploit CVE-2025-9526?
Yes, CVE-2025-9526 can be exploited remotely without physical access to the affected router.