VendorsLinksyse5600any version
Vulnerabilities

Linksys E5600 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2025-45488
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.
Published 2025-05-06 · Analyzed
9.8EPSS 0.111
CVE-2025-45487
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.
Published 2025-05-06 · Analyzed
9.8EPSS 0.110
CVE-2024-33789
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.
Published 2024-05-03 · Analyzed
9.8EPSS 0.024
CVE-2025-45491
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.
Published 2025-05-06 · Analyzed
9.8EPSS 0.020
CVE-2025-45489
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.
Published 2025-05-06 · Analyzed
9.8EPSS 0.018
CVE-2025-45490
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.
Published 2025-05-06 · Analyzed
9.8EPSS 0.017
CVE-2025-29228
Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.
Published 2025-12-23 · Analyzed
9.8EPSS 0.013
CVE-2025-29229
linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.
Published 2025-12-23 · Analyzed
9.8EPSS 0.013
CVE-2025-29230
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter.
Published 2025-03-21 · Analyzed
8.6EPSS 0.008
CVE-2025-9146
Linksys E5600 Firmware checkFw.sh verify_gemtek_header risky encryption
Published 2025-08-19 · Analyzed
8.1EPSS 0.005
CVE-2024-33788
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.
Published 2024-05-06 · Analyzed
8.0EPSS 0.019
CVE-2023-30305
An issue discovered in Linksys E5600 routers allows attackers to hijack TCP sessions which could lead to a denial of service.
Published 2024-05-28 · Analyzed
7.5EPSS 0.004
CVE-2025-29227
In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter.
Published 2025-03-21 · Analyzed
6.3EPSS 0.007
CVE-2025-29226
In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter.
Published 2025-03-21 · Analyzed
6.3EPSS 0.007
CVE-2025-29223
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function.
Published 2025-03-21 · Analyzed
6.3EPSS 0.007
CVE-2025-29231
A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hostname and domainName parameters.
Published 2025-12-16 · Analyzed
6.1EPSS 0.002
CVE-2025-22997
A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter.
Published 2025-01-14 · Analyzed
4.8EPSS 0.003
CVE-2025-22996
A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter.
Published 2025-01-14 · Analyzed
4.8EPSS 0.003