CVE-2025-44654 – Linksys E2500 vsftpd Unauthenticated Remote Command Execution Vulnerability

The following table lists the changes that have been made to the
CVE-2025-44654 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jul. 21, 2025

    Action Type Old Value New Value
    Added Description In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.
    Added Reference http://e2500.com
    Added Reference https://gist.github.com/TPCchecker/279708bf9c599c836ea66f3a3e0c25e1
Share the Post:

Related Posts