Junglewise Threat Intelligence

CVE-2025-44657: Linksys EA6350 improper access control in vsftpd configuration

CVE-2025-44657 · Severity: low · CVSS 3.9 · Published 2025-07-21

Vendors: Linksys.

Executive brief

A security misconfiguration in the Linksys EA6350 router's file transfer service could allow a user with limited access to gain broader control over the device. This could lead to the exposure of sensitive system files or allow an attacker to use the router as a jumping-off point to attack other devices on the home or office network. The risk is primarily to the privacy of data stored on or passing through the router.

Technical details

The vulnerability exists in the Linksys EA6350 router (firmware version 2.1.2) due to an insecure configuration of the vsftpd (Very Secure FTP Daemon) service. Specifically, the 'chroot_local_user' option is enabled in the dynamically generated configuration file without accompanying security restrictions. In certain vsftpd versions, enabling chroot without making the root directory non-writable can be exploited by a local user to escape the restricted environment. An attacker with local access or low-privileged credentials could leverage this to access sensitive system files, escalate privileges, or pivot to other internal network resources. The attack requires local access and potentially some user interaction.

Affected products

  • Linksys EA6350 Firmware 2.1.2

Timeline

  • 2025-07-21: advisory: Initial NVD publication

References