CVE-2025-29228: Command Injection
Published Dec 23, 2025
·Updated
Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.
Affected Software
3 affected components
LinkSys E5600
All of the following
LinkSys E5600 Firmware=1.1.0.26
LinkSys E5600
Event History
Dec 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29228?
CVE-2025-29228 is classified as a high severity vulnerability due to the potential for remote command injection.
2
How do I fix CVE-2025-29228?
To fix CVE-2025-29228, update the Linksys E5600 firmware to the latest version released by the vendor.
3
What does the CVE-2025-29228 vulnerability allow an attacker to do?
CVE-2025-29228 allows an attacker to perform command injection through the mc.ip parameter, potentially allowing unauthorized access or control.
4
Which devices are affected by CVE-2025-29228?
CVE-2025-29228 specifically affects the Linksys E5600 router running firmware version V1.1.0.26.
5
When was CVE-2025-29228 disclosed?
CVE-2025-29228 was disclosed in 2025, highlighting a critical security issue in certain Linksys routers.