PT-2025-19967 · Linksys · Linksys E5600

CVE-2025-45491

·

Published

2025-05-06

·

Updated

2025-05-07

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linksys E5600 version 1.1.0.26
Description A command injection issue was discovered in the runtime.ddnsStatus DynDNS function, specifically via the username parameter. This allows for potential exploitation.
Recommendations For Linksys E5600 version 1.1.0.26, avoid using the username parameter in the runtime.ddnsStatus DynDNS function until a fix is available. As a temporary workaround, consider restricting access to the DynDNS function to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-11326
CVE-2025-45491

Affected Products

Linksys E5600