Linksys E5600 Firmware vulnerabilities

17 known vulnerabilities affecting linksys/e5600_firmware.

Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH3MEDIUM6

Vulnerabilities

Page 1 of 1
CVE-2025-29228CRITICALCVSS 9.8v1.1.0.262025-12-23
CVE-2025-29228 [CRITICAL] CWE-77 CVE-2025-29228: Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.
nvd
CVE-2025-29229CRITICALCVSS 9.8v1.1.0.262025-12-23
CVE-2025-29229 [CRITICAL] CWE-77 CVE-2025-29229: linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus. linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.
nvd
CVE-2025-29231MEDIUMCVSS 6.1v1.1.0.262025-12-16
CVE-2025-29231 [MEDIUM] CWE-79 CVE-2025-29231: A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0 A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hostname and domainName parameters.
nvd
CVE-2025-9146HIGHCVSS 7.5v1.1.0.262025-08-19
CVE-2025-9146 [HIGH] CWE-310 CVE-2025-9146: A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_ A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_header of the file checkFw.sh of the component Firmware Handler. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is described as diff
nvd
CVE-2025-45488CRITICALCVSS 9.8v1.1.0.262025-05-06
CVE-2025-45488 [CRITICAL] CWE-77 CVE-2025-45488: Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.d Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.
nvd
CVE-2025-45490CRITICALCVSS 9.8v1.1.0.262025-05-06
CVE-2025-45490 [CRITICAL] CWE-77 CVE-2025-45490: Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.d Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.
nvd
CVE-2025-45487CRITICALCVSS 9.8v1.1.0.262025-05-06
CVE-2025-45487 [CRITICAL] CWE-77 CVE-2025-45487: Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.I Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.
nvd
CVE-2025-45491CRITICALCVSS 9.8v1.1.0.262025-05-06
CVE-2025-45491 [CRITICAL] CWE-77 CVE-2025-45491: Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.d Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.
nvd
CVE-2025-45489CRITICALCVSS 9.8v1.1.0.262025-05-06
CVE-2025-45489 [CRITICAL] CWE-77 CVE-2025-45489: Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.d Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.
nvd
CVE-2025-29230HIGHCVSS 8.6v1.1.0.262025-03-21
CVE-2025-29230 [HIGH] CWE-77 CVE-2025-29230: Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.e Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter.
nvd
CVE-2025-29223MEDIUMCVSS 6.3v1.1.0.262025-03-21
CVE-2025-29223 [MEDIUM] CWE-77 CVE-2025-29223: Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt param Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function.
nvd
CVE-2025-29226MEDIUMCVSS 6.3v1.1.0.262025-03-21
CVE-2025-29226 [MEDIUM] CWE-77 CVE-2025-29226: In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnera In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter.
nvd
CVE-2025-29227MEDIUMCVSS 6.3v1.1.0.262025-03-21
CVE-2025-29227 [MEDIUM] CWE-77 CVE-2025-29227: In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnera In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter.
nvd
CVE-2025-22997MEDIUMCVSS 4.8v1.1.0.262025-01-15
CVE-2025-22997 [MEDIUM] CWE-79 CVE-2025-22997: A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E560 A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter.
nvd
CVE-2025-22996MEDIUMCVSS 4.8v1.1.0.262025-01-15
CVE-2025-22996 [MEDIUM] CWE-79 CVE-2025-22996: A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E560 A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter.
nvd
CVE-2024-33788HIGHCVSS 8.0v1.1.0.262024-05-06
CVE-2024-33788 [HIGH] CWE-77 CVE-2024-33788: Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.
nvd
CVE-2024-33789CRITICALCVSS 9.8v1.1.0.262024-05-03
CVE-2024-33789 [CRITICAL] CWE-77 CVE-2024-33789: Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl pa Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.
nvd