CVE-2025-60692

8.4

Cisco · Linksys E1200 v2

A stack-based buffer overflow in the libshared.so library of Cisco Linksys E1200 v2 routers allows local attackers to trigger memory corruption or arbitrary code execution.

Executive summary

A critical stack-based buffer overflow vulnerability in Cisco Linksys E1200 v2 routers poses a severe risk of arbitrary code execution and system compromise.

Vulnerability

The functions get_mac_from_ip and get_ip_from_mac utilize insecure sscanf format specifiers when parsing /proc/net/arp, allowing an attacker with local access to trigger a stack-based buffer overflow.

Business impact

The vulnerability carries a CVSS score of 8.4, reflecting a high potential for total system compromise. Successful exploitation allows for memory corruption, denial of service, or arbitrary code execution, which could result in unauthorized access to sensitive network traffic or complete loss of control over the affected router.

Remediation

Immediate Action: Since no official patch is currently identified, users should restrict physical and local network access to these devices to prevent exploitation by unauthorized actors.

Proactive Monitoring: Security teams should monitor device logs for unexpected crashes or service restarts that may indicate memory corruption attempts against the libshared library.

Compensating Controls: Ensure that administrative access to the router is restricted to trusted management interfaces and disable any unnecessary services that might expose the vulnerable library functions.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists as documented in the technical write-up referenced in the CVE record.

Analyst recommendation

Given the severity of potential arbitrary code execution, organizations using the Cisco Linksys E1200 v2 should prioritize isolating these devices from critical network segments. If firmware updates are not provided by the vendor, decommissioning the affected hardware is the most effective strategy to eliminate the risk of exploitation.

More Cisco CVEs

Sources