cbcvebase.
CVE-2025-45487
published 2025-05-06

CVE-2025-45487: Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.

PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
10.98%
95.7th percentile
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.

Affected

1 ranges
VendorProductVersion rangeFixed in
linksyse5600_firmware——

Detection & IOCsextracted from sources · hover to see the quote

url/API/obj
bytes
|22|StaticipP|22|
bytes
|22|ifname|22 3a 22|
  • →Exploit targets HTTP POST requests to the exact 8-byte URI /API/obj on the Linksys E5600 management interface.
  • →Injection payload is delivered in the HTTP request body within the 'ifname' JSON parameter, alongside the 'StaticipP' key — look for shell metacharacters: semicolon (;/%3B), newline (\x0a/%0A), backtick (`/%60), pipe (|/%7C), dollar sign ($/%24), or double-ampersand (&&/%26%26).
  • →Traffic must be plaintext (TLS state: plaintext) and is best detected at the network perimeter or internally on traffic destined to networking equipment.
  • →The Cookie header must be present in the request — its absence may indicate a non-exploiting probe rather than a full attack attempt.
  • ·Vulnerability is confirmed only in Linksys E5600 firmware version v1.1.0.26; other versions are not confirmed affected. ↗
  • ·The Snort/Suricata rule (sid:2062420) uses a PCRE with the /R (relative) flag anchored after the ifname JSON key match — ensure your IDS/IPS engine supports PCRE relative matching to avoid false negatives.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.