Command Injection Vulnerability in Linksys E5600 by Linksys
CVE-2025-29227
6.3MEDIUM
What is CVE-2025-29227?
The Linksys E5600 version V1.1.0.26 is impacted by a command injection vulnerability located in the runtime.pingTest function of the runtime.lua file. This vulnerability can be exploited through a crafted request utilizing the pt["pkgsize"] parameter, allowing attackers to execute arbitrary commands on the affected device. It is crucial for users of the Linksys E5600 to take precautions and apply necessary updates to mitigate potential risks.