linksys e5600_firmware CVE Vulnerabilities (18)

CVEs: 18 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting linksys e5600_firmware (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 118 of 18 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-29229 linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus. [email protected] 9.8 1.13% 2025-12-23 2026-06-17
CVE-2025-29228 Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter. [email protected] 9.8 1.13% 2025-12-23 2026-06-17
CVE-2025-29231 A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hostname and domainName parameters. [email protected] 6.1 0.15% 2025-12-16 2026-06-17
CVE-2025-9146 A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_header of the file checkFw.sh of the component Firmware Handler. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is described as difficult. The vendor was contacted early about this disclosure but did not respond in any way. [email protected] 7.5 0.48% 2025-08-19 2026-06-17
CVE-2025-45491 Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter. [email protected] 9.8 2.05% 2025-05-06 2026-06-17
CVE-2025-45490 Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter. [email protected] 9.8 1.73% 2025-05-06 2026-06-17
CVE-2025-45489 Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter. [email protected] 9.8 1.91% 2025-05-06 2026-06-17
CVE-2025-45488 Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter. [email protected] 9.8 9.65% 2025-05-06 2026-06-17
CVE-2025-45487 Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function. [email protected] 9.8 9.56% 2025-05-06 2026-06-17
CVE-2025-29230 Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter. [email protected] 8.6 0.72% 2025-03-21 2026-06-17
CVE-2025-29227 In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter. [email protected] 6.3 0.70% 2025-03-21 2026-06-17
CVE-2025-29226 In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter. [email protected] 6.3 0.70% 2025-03-21 2026-06-17
CVE-2025-29223 Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function. [email protected] 6.3 0.70% 2025-03-21 2026-06-17
CVE-2025-22997 A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter. [email protected] 4.8 0.28% 2025-01-14 2026-06-17
CVE-2025-22996 A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter. [email protected] 4.8 0.28% 2025-01-14 2026-06-17
CVE-2023-30305 An issue discovered in Linksys E5600 routers allows attackers to hijack TCP sessions which could lead to a denial of service. [email protected] 7.5 0.42% 2024-05-28 2026-06-17
CVE-2024-33788 Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint. [email protected] 8.0 1.95% 2024-05-06 2026-06-17
CVE-2024-33789 Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint. [email protected] 9.8 2.38% 2024-05-03 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence