CVE-2025-29230: Command Injection
Published Mar 21, 2025
·Updated
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the pt["email"] parameter.
Affected Software
3 affected components
LinkSys E5600
All of the following
LinkSys E5600 Firmware=1.1.0.26
LinkSys E5600
Event History
Mar 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29230?
CVE-2025-29230 is considered a critical command injection vulnerability that can lead to unauthorized command execution.
2
How do I fix CVE-2025-29230?
To fix CVE-2025-29230, you should update the Linksys E5600 to the latest firmware version provided by the vendor.
3
What is affected by CVE-2025-29230?
CVE-2025-29230 affects the Linksys E5600 router, specifically version 1.1.0.26.
4
What are the potential impacts of CVE-2025-29230?
The potential impacts of CVE-2025-29230 include unauthorized access to the device and the ability to execute arbitrary commands.
5
How can the CVE-2025-29230 vulnerability be exploited?
CVE-2025-29230 can be exploited via malicious input to the `pt["email"]` parameter in the runtime.emailReg function.