CVE Tools

E5600 Firmware

18 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for E5600 Firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

E5600 Firmware CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
E5600 Firmware CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-012
2025-020
2025-034
2025-040
2025-055
2025-060
2025-070
2025-081
2025-090
2025-100
2025-110
2025-123
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 18 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical844%
  • High317%
  • Medium739%

Latest CVEs

The 15 most recently published vulnerabilities affecting E5600 Firmware.

  1. CVE-2025-29228Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.9.8
  2. CVE-2025-29229linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.9.8
  3. CVE-2025-29231A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into...6.1
  4. CVE-2025-9146Linksys E5600 Firmware checkFw.sh verify_gemtek_header risky encryption6.6
  5. CVE-2025-45489Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.9.8
  6. CVE-2025-45487Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.9.8
  7. CVE-2025-45491Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.9.8
  8. CVE-2025-45490Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.9.8
  9. CVE-2025-45488Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.9.8
  10. CVE-2025-29223Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function.6.3
  11. CVE-2025-29226In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter.6.3
  12. CVE-2025-29230Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter.8.6
  13. CVE-2025-29227In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter.6.3
  14. CVE-2025-22997A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted pa...4.8
  15. CVE-2025-22996A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted pa...4.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store