CVE-2025-29226: Command Injection
Published Mar 21, 2025
·Updated
In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter.
Affected Software
3 affected components
LinkSys E5600
All of the following
LinkSys E5600 Firmware=1.1.0.26
LinkSys E5600
Event History
Mar 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29226?
CVE-2025-29226 is classified as a high severity vulnerability due to the potential for command injection.
2
How do I fix CVE-2025-29226?
To fix CVE-2025-29226, update the Linksys E5600 router to the latest firmware version provided by the vendor.
3
What is the impact of CVE-2025-29226?
The impact of CVE-2025-29226 allows an attacker to execute arbitrary commands on the device, potentially leading to system compromise.
4
Which devices are affected by CVE-2025-29226?
CVE-2025-29226 affects the Linksys E5600 router running firmware version 1.1.0.26.
5
Is CVE-2025-29226 being actively exploited?
As of now, there have been no confirmed reports of active exploitation of CVE-2025-29226 in the wild.