CVE-2025-22996: XSS
Published Jan 14, 2025
·Updated
A stored cross-site scripting (XSS) vulnerability in the spftablecontent component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter.
Affected Software
3 affected components
LinkSys E5600 Router
All of the following
LinkSys E5600 Firmware=1.1.0.26
LinkSys E5600
Event History
Jan 14, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 15, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-22996?
The severity of CVE-2025-22996 is classified as high due to its potential for executing arbitrary scripts.
2
How do I fix CVE-2025-22996?
To mitigate CVE-2025-22996, update the Linksys E5600 Router to the latest firmware version provided by Linksys.
3
Who is affected by CVE-2025-22996?
Users of the Linksys E5600 Router running version 1.1.0.26 are affected by CVE-2025-22996.
4
What kind of attacks can CVE-2025-22996 enable?
CVE-2025-22996 can enable attackers to conduct stored cross-site scripting (XSS) attacks on vulnerable routers.
5
Where is CVE-2025-22996 located within the router's system?
CVE-2025-22996 is located in the spf_table_content component of the Linksys E5600 Router.