📦

e5600

Vendor: linksys

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 13 Remote Access
Total CVEs 33 Total Indexed
Avg. EPSS 2.00% Exploit Prob.
Latest CVE CVE-2025-29229 Dec 23

Security Vulnerability Index

Page 1 / 4
9.8 CVSS

linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.

EPSS: 1.13%
9.8 CVSS

Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.

EPSS: 1.13%
6.1 CVSS

A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hostname and domainName parameters.

EPSS: 0.16%
7.5 CVSS

A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_header of the file checkFw.sh of the component Firmware Handler. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is described as difficult. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS: 0.53%
9.8 CVSS

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.

EPSS: 2.05%
9.8 CVSS

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.

EPSS: 1.73%
9.8 CVSS

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.

EPSS: 1.91%
9.8 CVSS

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.

EPSS: 9.65%
9.8 CVSS

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.

EPSS: 9.56%
8.6 CVSS

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter.

EPSS: 0.74%