CVE-2025-9527 | Linksys E1700 1.0.0.4.003 /goform/QoSSetup ack_policy stack-based overflow
A vulnerability was found in Linksys E1700 1.0.0.4.003. It has been classified as critical. This affects the function QoSSetup of the file /goform/QoSSetup. Performing manipulation of the argument ack_policy results in stack-based buffer overflow.
This vulnerability was named CVE-2025-9527. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.