Linksys
Linksys E5600 Firmware: vulnerabilidades y CVE
Linksys E5600 Firmware tiene 18 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses3
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-29229 | Crítica (9.8) | 1.3% | — | 23 dic 2025 | linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus. |
| CVE-2025-29228 | Crítica (9.8) | 1.3% | — | 23 dic 2025 | Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter. |
| CVE-2025-29231 | Media (6.1) | 0.19% | — | 16 dic 2025 | A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hostname and… |
| CVE-2025-9146 | Alta (7.5) | 0.53% | — | 19 ago 2025 | A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_header of the file checkFw.sh of the component Firmware Handler. Executing manipulation can lead to risky cryptographic… |
| CVE-2025-45491 | Crítica (9.8) | 1.9% | — | 6 may 2025 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter. |
| CVE-2025-45490 | Crítica (9.8) | 1.8% | — | 6 may 2025 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter. |
| CVE-2025-45489 | Crítica (9.8) | 1.8% | — | 6 may 2025 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter. |
| CVE-2025-45488 | Crítica (9.8) | 12% | — | 6 may 2025 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter. |
| CVE-2025-45487 | Crítica (9.8) | 11% | — | 6 may 2025 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function. |
| CVE-2025-29230 | Alta (8.6) | 0.78% | — | 21 mar 2025 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter. |
| CVE-2025-29227 | Media (6.3) | 0.66% | — | 21 mar 2025 | In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter. |
| CVE-2025-29226 | Media (6.3) | 0.66% | — | 21 mar 2025 | In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter. |
| CVE-2025-29223 | Media (6.3) | 0.66% | — | 21 mar 2025 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function. |
| CVE-2025-22997 | Media (4.8) | 0.31% | — | 15 ene 2025 | A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into… |
| CVE-2025-22996 | Media (4.8) | 0.31% | — | 15 ene 2025 | A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into… |
| CVE-2023-30305 | Alta (7.5) | 0.42% | — | 28 may 2024 | An issue discovered in Linksys E5600 routers allows attackers to hijack TCP sessions which could lead to a denial of service. |
| CVE-2024-33788 | Alta (8) | 1.9% | — | 6 may 2024 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint. |
| CVE-2024-33789 | Crítica (9.8) | 2.4% | — | 3 may 2024 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.