Home

Description

In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

PUBLISHED Reserved 2025-04-22 | Published 2025-07-21 | Updated 2025-07-22 | Assigner mitre

References

ea6350.com

gist.github.com/TPCchecker/7839fbd329ebd2f9f6b105c4926d4b0c

cve.org (CVE-2025-44657)

nvd.nist.gov (CVE-2025-44657)

Download JSON