CVE-2025-45490
published 2025-05-06CVE-2025-45490: Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.
PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.68%
75.5th percentile
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linksys | e5600_firmware | — | — |
| msrc | azl3_cmake_3.30.3-6_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.3-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.3-5_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_cmake_3.21.4-17_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.2-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.3-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-13_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlhttps://github.com/JZP018/vuln03/blob/main/linksys/E5600
path/API/obj
cookie|0d 0a|cookie|0d 0a|
commandPOST /API/obj with body containing "DdnsP" and shell metacharacters (;|%3B, newline|%0A, backtick|%60, pipe|%7C, $|%24, &&|%26%26) in hostname/mailex/username/password parameters
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Linksys E5600 runtime.ddnsStatus Multiple Parameters Command Injection Attempt (CVE-2025-45488-2025-45491)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:8; content:"/API/obj"; http.header_names; to_lowercase; content:"|0d 0a|cookie|0d 0a|"; http.request_body; content:"|22|DdnsP|22|"; fast_pattern; pcre:"/\x22(?:hostname|mailex|username|password).*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24)|(?:\x26{2}|%26%26))+/"; reference:cve,2025-45488; reference:cve,2025-45489; reference:cve,2025-45490; reference:cve,2025-45491; reference:url,github.com/JZP018/vuln03/blob/main/linksys/E5600; classtype:attempted-admin; sid:2062421; rev:1; metadata:affected_product Linksys, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_05_19, cve CVE_2025_45488, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, updated_at 2025_05_19, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)bytes
|22|DdnsP|22|
- →Target the runtime.ddnsStatus DynDNS function; exploit arrives as an HTTP POST to the exact 8-byte URI /API/obj with a Cookie header present and a JSON body containing the key 'DdnsP'
- →Injection is carried in the password parameter (and also hostname, mailex, username per the broader rule family) using shell metacharacters: semicolon, newline, backtick, pipe, dollar-sign, or double-ampersand — both raw and URL-encoded forms must be matched
- →Traffic is expected in plaintext (TLS state: plaintext); deploy detection at the network perimeter and internally facing Linksys E5600 devices
- →CVE-2025-45490 is part of a cluster (CVE-2025-45488 through CVE-2025-45491) all exploiting the same runtime.ddnsStatus endpoint; a single Snort/Suricata rule (sid:2062421) covers all four CVEs
- ·Vulnerability is confirmed only on Linksys E5600 firmware version v1.1.0.26; other firmware versions are not mentioned as affected ↗
- ·The Snort rule URI match uses bsize:8 (exact length), so any path padding or API versioning changes would bypass this detection; validate the URI pattern against your device's actual API surface
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-phr9-h376-r6rq: Linksys E5600 v1
ghsa_unreviewed·2025-05-06
CVE-2025-45490 [MEDIUM] CWE-77 GHSA-phr9-h376-r6rq: Linksys E5600 v1
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.
Microsoft
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
vendor_msrc·2024-08-13·CVSS 7.5
CVE-2024-45490 [HIGH] CWE-611 An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Suricata
ET WEB_SPECIFIC_APPS Linksys E5600 runtime.ddnsStatus Multiple Parameters Command Injection Attempt (CVE-2025-45488-2025-45491)
suricata·2025-05-19·CVSS 9.8
CVE-2025-45488 [CRITICAL] ET WEB_SPECIFIC_APPS Linksys E5600 runtime.ddnsStatus Multiple Parameters Command Injection Attempt (CVE-2025-45488-2025-45491)
ET WEB_SPECIFIC_APPS Linksys E5600 runtime.ddnsStatus Multiple Parameters Command Injection Attempt (CVE-2025-45488-2025-45491)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Linksys E5600 runtime.ddnsStatus Multiple Parameters Command Injection Attempt (CVE-2025-45488-2025-45491)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:8; content:"/API/obj"; http.header_names; to_lowercase; content:"|0d 0a|cookie|0d 0a|"; http.request_body; content:"|22|DdnsP|22|"; fast_pattern; pcre:"/\x22(?:hostname|mailex|username|password).*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24)|(?:\x26{2}|%26%26))+/"; reference:cve,2025-45488; reference:cve,2025-45489; reference:cve,2025-45490; reference:cve,2025-45491; reference:url,gith
No public exploits indexed.
No writeups or analysis indexed.
2025-05-06
Published