Vulnerability Description
A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The functions get_mac_from_ip and get_ip_from_mac use sscanf with overly permissive "%100s" format specifiers to parse entries from /proc/net/arp into fixed-size buffers (v6: 50 bytes, v7 sub-arrays: 50 bytes). This allows local attackers controlling the contents of /proc/net/arp to overflow stack buffers, leading to memory corruption, denial of service, or potential arbitrary code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linksys | E1200 Firmware | 2.0.11.001 |
| Linksys | E1200 | 2 |
Related Weaknesses (CWE)
References
- http://linksys.comProduct
- https://github.com/yifan20020708/SGTaint-0-day/blob/main/Linksys/Linksys-E1200/CExploitThird Party Advisory
- https://www.linksys.com/Product
FAQ
What is CVE-2025-60692?
CVE-2025-60692 is a vulnerability with a CVSS score of 8.4 (HIGH). A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The functions get_mac_from_ip and get_ip_from_m...
How severe is CVE-2025-60692?
CVE-2025-60692 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-60692?
Check the references section above for vendor advisories and patch information. Affected products include: Linksys E1200 Firmware, Linksys E1200.