First published: Fri Mar 21 2025(Updated: )
In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linksys E5600 Firmware | ||
All of | ||
Linksys E5600 Firmware | =1.1.0.26 | |
Linksys E5600 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-29227 is considered a high severity vulnerability due to the potential for command injection exploitation.
To fix CVE-2025-29227, it is recommended to update the Linksys E5600 firmware to the latest version provided by the manufacturer.
CVE-2025-29227 is a command injection vulnerability found in the runtime.pingTest function related to the pt["pkgsize"] parameter.
CVE-2025-29227 specifically affects the Linksys E5600 router running firmware version V1.1.0.26.
CVE-2025-29227 can be exploited by sending specially crafted input to the runtime.pingTest function, allowing an attacker to execute arbitrary commands.