CVE-2003-0125

MultiTech RouteFinder 550 VPN < 4.63 - Buffer Overflow via Long GET OPTIONS Value

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0125. PoCs published by Peter Kruse.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in Multitech RouteFinder 550 VPN firmware via an overly long HTTP GET request. The PoC shows how excessive data in the request can corrupt memory, potentially leading to a denial of service or arbitrary command execution.

Description

Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a long GET /OPTIONS value.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Peter Kruse · textdosmultiple
https://www.exploit-db.com/exploits/22345

This exploit demonstrates a buffer overflow vulnerability in Multitech RouteFinder 550 VPN firmware via an overly long HTTP GET request. The PoC shows how excessive data in the request can corrupt memory, potentially leading to a denial of service or arbitrary command execution.

Classification
Working Poc 80%
Attack Type
Dos
Complexity
Trivial
Reliability
Theoretical
Target: Multitech RouteFinder 550 VPN firmware release 4.63 and earlier
No auth needed
Prerequisites: Network access to the vulnerable device
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Patch, Vendor Advisory x_refsource_misc
http://www.krusesecurity.dk/advisories/routefind550bof.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/11514
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/7067
Vendor Advisory x_refsource_confirm
ftp://ftp.multitech.com/Routers/RF550VPN.TXT

Scores

EPSS 0.1076
EPSS Percentile 95.4%

Details

Status published
Products (1)
multitech/routefinder_550_vpn < 4.63
Published Mar 18, 2003
Tracked Since Feb 18, 2026