Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Linksys E1700 Stack-Based Buffer Overflow Vulnerability in setSysAdm Function

Vulnerability

A stack-based buffer overflow vulnerability has been identified in the Linksys E1700 router running firmware version 1.0.0.4.003. The issue arises in the setSysAdm function, where the rm_port parameter is not properly validated, allowing remote attackers to overwrite the stack and potentially execute arbitrary code. This vulnerability can lead to a denial-of-service condition, causing the router to crash and disrupt normal operations.

Impact

Exploitation of this vulnerability causes the router to crash, leading to a persistent denial-of-service condition where the device fails to function correctly or provide services.

Reproduction

To reproduce this vulnerability, send a POST request to the /goform/setSysAdm endpoint. Include the rm_port parameter with a payload that is excessively long, which will cause the router to crash. The request should be made with authorization as an admin user.

Added: Aug 27, 2025, 1:17 PM
Updated: Aug 27, 2025, 1:17 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
9.4
remediation
0.0
relevance
0.4
threat
8.0
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.