Executive brief
A security flaw has been identified in the Linksys E2500 router, a device used to provide wireless internet connectivity. Due to a configuration error in the router's file transfer service, an attacker could gain unauthorized access to sensitive system files. This could allow a malicious actor to take control of the device, steal data, or use the router as a jumping-off point to attack other devices on your internal network.
Technical details
This vulnerability stems from an improper access control configuration within the vsftpd service on the Linksys E2500 router (firmware version 3.0.04.002). Specifically, the 'chroot_local_user' option is enabled in the vsftpd configuration file. While intended to restrict users to their home directories, certain versions of vsftpd are vulnerable to escapes or misconfigurations when this setting is active without additional security constraints (like 'allow_writeable_chroot'). An unauthenticated or low-privileged attacker can exploit this to bypass directory restrictions, gaining access to the underlying filesystem. This can result in full system compromise, privilege escalation, and the ability to use the router as a network pivot.
Affected products
- Linksys E2500 3.0.04.002
Timeline
- 2025-07-21: disclosed
- 2025-07-21: advisory