← Back

E5600 Firmware

e5600_firmware

Vendor: Linksys • 18 CVEs

CVEs (18)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Linksys
1E5600 Firmware
Jan 6, 2026
Dec 23, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.
1Linksys
1E5600 Firmware
Jan 6, 2026
Dec 23, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.
1Linksys
1E5600 Firmware
Dec 31, 2025
Dec 16, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hostname and domai...Show more
A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hostname and domainName parameters.Show less
1Linksys
1E5600 Firmware
Sep 12, 2025
Aug 19, 2025
7.5 HIGH· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_header of the file checkFw.sh of the component Firmware Handler. Executing manipulation can lead to risky cryptographic...Show more
A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_header of the file checkFw.sh of the component Firmware Handler. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is described as difficult. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Linksys
1E5600 Firmware
May 13, 2025
May 6, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.
1Linksys
1E5600 Firmware
May 13, 2025
May 6, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.
1Linksys
1E5600 Firmware
May 13, 2025
May 6, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.
1Linksys
1E5600 Firmware
May 13, 2025
May 6, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.
1Linksys
1E5600 Firmware
May 13, 2025
May 6, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.
1Linksys
1E5600 Firmware
Apr 1, 2025
Mar 21, 2025
N/A· v4
8.6 HIGH· v3
N/A· v2
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter.
1Linksys
1E5600 Firmware
Apr 1, 2025
Mar 21, 2025
N/A· v4
6.3 MEDIUM· v3
N/A· v2
In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter.
1Linksys
1E5600 Firmware
Apr 1, 2025
Mar 21, 2025
N/A· v4
6.3 MEDIUM· v3
N/A· v2
In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter.
1Linksys
1E5600 Firmware
Apr 1, 2025
Mar 21, 2025
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function.
1Linksys
1E5600 Firmware
Jun 11, 2025
Jan 15, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the...Show more
A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter.Show less
1Linksys
1E5600 Firmware
Jun 11, 2025
Jan 15, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the...Show more
A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter.Show less
1Linksys
1E5600 Firmware
Jun 10, 2025
May 28, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue discovered in Linksys E5600 routers allows attackers to hijack TCP sessions which could lead to a denial of service.
1Linksys
1E5600 Firmware
Jun 11, 2025
May 6, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.
1Linksys
1E5600 Firmware
Jun 10, 2025
May 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.