CVE-2025-45491
published 2025-05-06CVE-2025-45491: Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.99%
79.5th percentile
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linksys | e5600_firmware | — | — |
| msrc | azl3_cmake_3.30.3-6_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.3-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.3-5_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_cmake_3.21.4-17_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.2-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.3-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-13_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlhttps://github.com/JZP018/vuln03/blob/main/linksys/E5600
path/API/obj
cookie|0d 0a|cookie|0d 0a|
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Linksys E5600 runtime.ddnsStatus Multiple Parameters Command Injection Attempt (CVE-2025-45488-2025-45491)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:8; content:"/API/obj"; http.header_names; to_lowercase; content:"|0d 0a|cookie|0d 0a|"; http.request_body; content:"|22|DdnsP|22|"; fast_pattern; pcre:"/\x22(?:hostname|mailex|username|password).*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24)|(?:\x26{2}|%26%26))+/"; reference:cve,2025-45488; reference:cve,2025-45489; reference:cve,2025-45490; reference:cve,2025-45491; reference:url,github.com/JZP018/vuln03/blob/main/linksys/E5600; classtype:attempted-admin; sid:2062421; rev:1; metadata:affected_product Linksys, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_05_19, cve CVE_2025_45488, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, updated_at 2025_05_19, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)bytes
|22|DdnsP|22|
- →Exploit targets HTTP POST requests to the exact 8-byte URI /API/obj on the Linksys E5600 management interface.
- →Injection payload is carried in the HTTP request body within the DdnsP object fields; look for shell metacharacters (;, newline, backtick, pipe, $, &&) in the hostname, mailex, username, or password parameters.
- →Traffic is expected in plaintext (no TLS); deploy detection at the network perimeter and internally.
- →The vulnerability is in the runtime.ddnsStatus DynDNS function and is exploitable via the username parameter specifically for CVE-2025-45491. ↗
- →Snort/Suricata SID 2062421 (ET rule) covers this CVE alongside CVE-2025-45488, CVE-2025-45489, and CVE-2025-45490 — all targeting the same endpoint with different injectable parameters.
- ·The ET Snort rule (SID 2062421) covers four related CVEs (CVE-2025-45488 through CVE-2025-45491) with a single signature; a match does not isolate CVE-2025-45491 specifically — triage is required to confirm the username parameter was the injected field.
- ·The PCRE matches URL-encoded variants of shell metacharacters (%3B, %0A, %60, %7C, %24, %26%26), so WAF/IDS rules must handle both raw and percent-encoded forms to avoid bypass.
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-33xq-rr72-hjfj: Linksys E5600 v1
ghsa_unreviewed·2025-05-06
CVE-2025-45491 [CRITICAL] CWE-77 GHSA-33xq-rr72-hjfj: Linksys E5600 v1
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.
Microsoft
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
vendor_msrc·2024-08-13·CVSS 9.8
CVE-2024-45491 [CRITICAL] CWE-190 An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Marine
Suricata
ET WEB_SPECIFIC_APPS Linksys E5600 runtime.ddnsStatus Multiple Parameters Command Injection Attempt (CVE-2025-45488-2025-45491)
suricata·2025-05-19·CVSS 9.8
CVE-2025-45488 [CRITICAL] ET WEB_SPECIFIC_APPS Linksys E5600 runtime.ddnsStatus Multiple Parameters Command Injection Attempt (CVE-2025-45488-2025-45491)
ET WEB_SPECIFIC_APPS Linksys E5600 runtime.ddnsStatus Multiple Parameters Command Injection Attempt (CVE-2025-45488-2025-45491)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Linksys E5600 runtime.ddnsStatus Multiple Parameters Command Injection Attempt (CVE-2025-45488-2025-45491)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:8; content:"/API/obj"; http.header_names; to_lowercase; content:"|0d 0a|cookie|0d 0a|"; http.request_body; content:"|22|DdnsP|22|"; fast_pattern; pcre:"/\x22(?:hostname|mailex|username|password).*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24)|(?:\x26{2}|%26%26))+/"; reference:cve,2025-45488; reference:cve,2025-45489; reference:cve,2025-45490; reference:cve,2025-45491; reference:url,gith
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/JZP018/vuln03/blob/main/linksys/E5600/CI_ddnsStatus_DynDNS_username/CI_ddnsStatus_DynDNS_username.pdfhttps://github.com/JZP018/vuln03/blob/main/linksys/E5600/CI_ddnsStatus_DynDNS_username/CI_ddnsStatus_DynDNS_username.pyhttps://github.com/JZP018/vuln03/blob/main/linksys/E5600/CI_ddnsStatus_DynDNS_username/CI_ddnsStatus_DynDNS_username.pdf
2025-05-06
Published