Linksys E1700 Stack-Based Buffer Overflow Vulnerability in QoS Setup Function

Vulnerability

A stack-based buffer overflow vulnerability has been identified in the Linksys E1700 router running firmware version 1.0.0.4.003. The issue arises in the QoSSetup function of the file /goform/QoSSetup, where the ack_policy parameter is vulnerable to manipulation. This lack of input validation allows remote attackers to overwrite the stack, potentially leading to arbitrary code execution. Exploitation of this vulnerability causes the router to crash, disrupting its normal service.

Impact

Exploitation of this vulnerability leads to a stack-based buffer overflow, causing the router to crash and fail to provide services correctly and persistently.

Reproduction

The vulnerability can be reproduced by sending a POST request to the /goform/QoSSetup endpoint. The request must include a long string in the ack_policy parameter, which will overflow the buffer and crash the router. This can be done using a web browser or a tool like curl, with the appropriate headers and authorization.

Added: Aug 27, 2025, 2:24 PM
Updated: Aug 27, 2025, 2:24 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
5.8
remediation
0.0
relevance
0.4
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.