References https://www.anquanke.com/post/id/85125 https://stack.chaitin.com/vuldb/detail/e1dcae76-56c9-492a-be62-d1b30bf14788 https://www.iotsec-zone.com/article/235 http://www.icfj.cn/home/posts/260 https://blog.csdn.net/smellycat000/article/details/141908699 https://xxzx.aku.edu.cn/info/1222/2056.htm https://developer.aliyun.com/article/207440 https://www.51cto.com/article/796249.html https://www.sohu.com/a/806175971_354899 https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/iot/README.md http://www.cnetsec.com/article/20864.html https://www.iotsec-zone.com/article/312 https://net.zol.com.cn/618/6188754.html https://m.freebuf.com/news/403718.html https://www.8090-sec.com/archives/8075 https://www.anquanke.com/post/id/299826 https://vulncheck.com/advisories/linksys-routers-command-injection https://www.forescout.com/blog/new-tp-link-router-vulnerabilities-a-primer-on-rooting-routers/ https://unit42.paloaltonetworks.com/totolink-x6000r-vulnerabilities/ https://bbs.kanxue.com/thread-274713.htm
Related Vulnerabilities(CVE-2025-9355) Linksys多款路由器scheduleAdd参数ruleName基于堆栈的缓冲区溢出漏洞(CVE-2025-9358)Linksys多款路由器setSysAdm栈基缓冲区溢出漏洞(CVE-2025-9360)Linksys多款路由器accessControlAdd功能栈基缓冲区溢出漏洞(CVE-2025-9251)Linksys多款路由器sta_wps_pin函数栈溢出漏洞(CVE-2025-9249) Linksys多款路由器DHCPReserveAddGroup栈溢出漏洞可远程利用PoCsapido-router-rce: Sapido 多款路由器 远程命令执行漏洞TP_LINK 多款路由器命令执行(CVE-2020-9374)多款路由器命令注入漏洞(CVE-2019-3929)多款路由器ExportSettings.sh-文件下载