CVE-2014-125122 - CVE House
Back to Database
Status published Medium CVE-2014-125122

Linksys WRT120N tmUnblock.cgi Stack-Based Buffer Overflow Admin Password Reset

Vulnerability Description

A stack-based buffer overflow vulnerability exists in the tmUnblock.cgi endpoint of the Linksys WRT120N wireless router. The vulnerability is triggered by sending a specially crafted HTTP POST request with an overly long TM_Block_URL parameter to the endpoint. By exploiting this flaw, an unauthenticated remote attacker can overwrite memory in a controlled manner, enabling them to temporarily reset the administrator password of the device to a blank value. This grants unauthorized access to the router’s web management interface without requiring valid credentials.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-125122

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Craig Heffner

Affected Vendor

Affected Software

WRT120N
Vulnerable Versions:
1.0.07

Timeline

Official Publish: July 31st, 2025
Last Modified: April 7th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)