E5600 Firmware
18 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for E5600 Firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
E5600 Firmware CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 2 |
| 2025-02 | 0 |
| 2025-03 | 4 |
| 2025-04 | 0 |
| 2025-05 | 5 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 1 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 3 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 18 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical8
- High3
- Medium7
Latest CVEs
The 15 most recently published vulnerabilities affecting E5600 Firmware.
- CVE-2025-29228Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.9.8
- CVE-2025-29229linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.9.8
- CVE-2025-29231A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into...6.1
- CVE-2025-9146Linksys E5600 Firmware checkFw.sh verify_gemtek_header risky encryption6.6
- CVE-2025-45489Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.9.8
- CVE-2025-45487Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.9.8
- CVE-2025-45491Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.9.8
- CVE-2025-45490Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.9.8
- CVE-2025-45488Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.9.8
- CVE-2025-29223Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function.6.3
- CVE-2025-29226In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter.6.3
- CVE-2025-29230Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter.8.6
- CVE-2025-29227In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter.6.3
- CVE-2025-22997A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted pa...4.8
- CVE-2025-22996A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted pa...4.8
Product grouping is registry-driven, with AI assist and human review. How it works