Executive brief
A security vulnerability exists in the Linksys E7350 router, a device used to provide home and office internet connectivity. An attacker with local access to the device's file system could exploit a flaw in how the router handles network hardware addresses. This could lead to a system crash or allow the attacker to take control of the device, potentially compromising the security of the local network.
Technical details
A stack-based buffer overflow exists in the 'mtk_dut' binary of the Linksys E7350 router within the 'sub_4045A8' function. The vulnerability is triggered when the function reads up to 256 bytes from a system file (/sys/class/net/%s/address) using 'fgets' and subsequently copies that data into a destination buffer ('a1') using 'strcpy' without performing boundary checks. Because the destination buffers in the call chain are significantly smaller (ranging from 20 to 32 bytes), an attacker who can control the contents of the system network address files can overflow the stack. This can result in memory corruption, denial of service, or arbitrary code execution. This is a local attack requiring the ability to modify system files or filesystem write permissions.
Affected products
- Linksys E7350 Router 1.1.00.032
Timeline
- 2025-11-13: advisory: NVD publication date