CVE-2025-29227: Command Injection
In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29227?
CVE-2025-29227 is considered a high severity vulnerability due to the potential for command injection exploitation.
How do I fix CVE-2025-29227?
To fix CVE-2025-29227, it is recommended to update the Linksys E5600 firmware to the latest version provided by the manufacturer.
What is the nature of the vulnerability in CVE-2025-29227?
CVE-2025-29227 is a command injection vulnerability found in the runtime.pingTest function related to the pt["pkgsize"] parameter.
Which devices are affected by CVE-2025-29227?
CVE-2025-29227 specifically affects the Linksys E5600 router running firmware version V1.1.0.26.
How can CVE-2025-29227 be exploited?
CVE-2025-29227 can be exploited by sending specially crafted input to the runtime.pingTest function, allowing an attacker to execute arbitrary commands.