VYPR

E5600

by Linksys

CVEs (18)

  • CVE-2025-45491CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.

  • CVE-2025-45490CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.

  • CVE-2025-45489CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.02

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.

  • CVE-2025-45488CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.09

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.

  • CVE-2025-45487CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.09

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.

  • CVE-2024-33789CriMay 3, 2024
    risk 0.64cvss 9.8epss 0.02

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.

  • CVE-2025-29230HigMar 21, 2025
    risk 0.56cvss 8.6epss 0.01

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter.

  • CVE-2024-33788HigMay 6, 2024
    risk 0.52cvss 8.0epss 0.02

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.

  • CVE-2023-30305HigMay 28, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue discovered in Linksys E5600 routers allows attackers to hijack TCP sessions which could lead to a denial of service.

  • CVE-2025-29227MedMar 21, 2025
    risk 0.41cvss 6.3epss 0.01

    In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter.

  • CVE-2025-29226MedMar 21, 2025
    risk 0.41cvss 6.3epss 0.01

    In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter.

  • CVE-2025-29223MedMar 21, 2025
    risk 0.41cvss 6.3epss 0.01

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function.

  • CVE-2025-22997MedJan 15, 2025
    risk 0.31cvss 4.8epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter.

  • CVE-2025-22996MedJan 15, 2025
    risk 0.31cvss 4.8epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter.

  • CVE-2025-29228Dec 23, 2025
    risk 0.00cvss epss 0.01

    Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.

  • CVE-2025-29229Dec 23, 2025
    risk 0.00cvss epss 0.01

    linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.

  • CVE-2025-29231Dec 16, 2025
    risk 0.00cvss epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hostname and domainName parameters.

  • CVE-2025-9146Aug 19, 2025
    risk 0.00cvss epss 0.00

    A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_header of the file checkFw.sh of the component Firmware Handler. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. The attack…