First published: Fri Mar 21 2025(Updated: )
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linksys E5600 Firmware | ||
All of | ||
Linksys E5600 Firmware | =1.1.0.26 | |
Linksys E5600 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-29230 is considered a critical command injection vulnerability that can lead to unauthorized command execution.
To fix CVE-2025-29230, you should update the Linksys E5600 to the latest firmware version provided by the vendor.
CVE-2025-29230 affects the Linksys E5600 router, specifically version 1.1.0.26.
The potential impacts of CVE-2025-29230 include unauthorized access to the device and the ability to execute arbitrary commands.
CVE-2025-29230 can be exploited via malicious input to the `pt["email"]` parameter in the runtime.emailReg function.