Linksys RE6500
cpe:2.3:o:linksys:re6500_firmware:*:*:*:*:*:*:*
- 1.0.013.001
- 1.0.04.001
- 1.2.07.001
- 1.1.05.003
- 1.0.04.002
A stack-based buffer overflow vulnerability has been identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000, and RE9000 routers running specific firmware versions. The vulnerability resides in the 'portRangeForwardAdd' function of the '/goform/portRangeForwardAdd' file. It allows remote attackers to manipulate several unvalidated input parameters, including 'ruleName', 'schedule', 'inboundFilter', 'TCPPorts', and 'UDPPorts', leading to a stack overflow condition. This overflow can be exploited to execute arbitrary code, causing the router to crash and disrupt its normal services.
Exploitation of this vulnerability leads to a stack-based buffer overflow, allowing for arbitrary code execution. However, in the context of the proof-of-concept demonstration, the exploitation causes the router to crash, disrupting its services permanently.
To reproduce this vulnerability, send a POST request to the '/goform/portRangeForwardAdd' endpoint. Include a 'ruleName' parameter with a payload that exceeds the buffer's capacity. The router will crash, indicating successful exploitation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.