Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-44654


In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.


Published

2025-07-21T18:15:27.817

Last Modified

2026-01-02T21:03:26.243

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System linksys e2500_firmware 3.0.04.002 Yes
Hardware linksys e2500 - No

References