CVE-2025-45487
published 2025-05-06CVE-2025-45487: Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.
PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
10.98%
95.7th percentile
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linksys | e5600_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
url/API/obj
bytes
|22|StaticipP|22|
bytes
|22|ifname|22 3a 22|
- →Exploit targets HTTP POST requests to the exact 8-byte URI /API/obj on the Linksys E5600 management interface.
- →Injection payload is delivered in the HTTP request body within the 'ifname' JSON parameter, alongside the 'StaticipP' key — look for shell metacharacters: semicolon (;/%3B), newline (\x0a/%0A), backtick (`/%60), pipe (|/%7C), dollar sign ($/%24), or double-ampersand (&&/%26%26).
- →Traffic must be plaintext (TLS state: plaintext) and is best detected at the network perimeter or internally on traffic destined to networking equipment.
- →The Cookie header must be present in the request — its absence may indicate a non-exploiting probe rather than a full attack attempt.
- ·Vulnerability is confirmed only in Linksys E5600 firmware version v1.1.0.26; other versions are not confirmed affected. ↗
- ·The Snort/Suricata rule (sid:2062420) uses a PCRE with the /R (relative) flag anchored after the ifname JSON key match — ensure your IDS/IPS engine supports PCRE relative matching to avoid false negatives.
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Linksys E5600 CI_InternetConnection ifname Parameter Command Injection Attempt (CVE-2025-45487)
suricata·2025-05-19·CVSS 9.8
CVE-2025-45487 [CRITICAL] ET WEB_SPECIFIC_APPS Linksys E5600 CI_InternetConnection ifname Parameter Command Injection Attempt (CVE-2025-45487)
ET WEB_SPECIFIC_APPS Linksys E5600 CI_InternetConnection ifname Parameter Command Injection Attempt (CVE-2025-45487)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Linksys E5600 CI_InternetConnection ifname Parameter Command Injection Attempt (CVE-2025-45487)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:8; content:"/API/obj"; http.header_names; to_lowercase; content:"|0d 0a|cookie|0d 0a|"; http.request_body; content:"|22|StaticipP|22|"; fast_pattern; content:"|22|ifname|22 3a 22|"; pcre:"/^.*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24)|(?:\x26{2}|%26%26))+/R"; reference:cve,2025-45487; reference:url,github.com/JZP018/vuln03/blob/main/linksys/E5600/CI_InternetConnection/CI_InternetConnection.pdf; classtype
No public exploits indexed.
No writeups or analysis indexed.
2025-05-06
Published