← Vulnerability feed

Vulnerability record · CVE-2025-60691 · published 13 November 2025

CVE-2025-60691: Linksys e1200 firmware stack-based buffer overflow vulnerability

Linksys · E1200 Firmware

A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The apply_cgi and block_cgi functions copy user-supplied input from the "url" CGI parameter into stack buffers (v36, v29) using sprintf without bounds checking. Because these buffers are allocated as single-byte variables, any non-empty input will trigger a buffer overflow. Remote attackers can exploit this vulnerability via crafted HTTP requests to execute arbitrary code or cause denial of service without authentication.

8.8 CVSS 3.1 High EPSS 0.71% · top 48.2% CWE-121 · Stack-based buffer overflow
8.8CVSS 3.1 base score
0.71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
5 Jul 2026Last modified by NVD

Description

A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The apply_cgi and block_cgi functions copy user-supplied input from the "url" CGI parameter into stack buffers (v36, v29) using sprintf without bounds checking. Because these buffers are allocated as single-byte variables, any non-empty input will trigger a buffer overflow. Remote attackers can exploit this vulnerability via crafted HTTP requests to execute arbitrary code or cause denial of service without authentication.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-60691 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-38555Linksys e1200 firmware out-of-bounds write vulnerabilityLinksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.EPSS 9.8%8.8CVE-2025-60690Linksys e1200 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.…EPSS 3.9%8.4CVE-2025-60692Linksys e1200 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.g…EPSS 0.23%7.5CVE-2025-60694Linksys e1200 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow exists in the validate_static_route function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.00…EPSS 1.1%7.2CVE-2018-3953Linksys e1200 firmware os command injection vulnerabilityDevices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to O…EPSS 14%7.2CVE-2018-3954Linksys e1200 firmware os command injection vulnerabilityDevices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to O…EPSS 3.4%7.2CVE-2018-3955Linksys e1200 firmware os command injection vulnerabilityAn exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2…EPSS 4.8%6.5CVE-2025-60693Linksys e1200 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow exists in the get_merge_mac function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar…EPSS 0.77%

Source: NIST National Vulnerability Database (record CVE-2025-60691), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.