In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.
2025-07-21T16:15:29.443
2025-08-07T17:58:03.430
Analyzed
CVSSv3.1: 3.9 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linksys | ea6350_firmware | 2.1.2 | Yes |
Hardware | linksys | ea6350 | - | No |