CVE-2025-29228

9.8

Linksys · E5600

Linksys E5600 firmware V1.1.0.26 contains a command injection vulnerability in the runtime.macClone function via the mc.ip parameter.

Executive summary

A critical command injection vulnerability in the Linksys E5600 router allows unauthenticated attackers to execute arbitrary system commands, posing a severe risk of full device compromise.

Vulnerability

This is a command injection vulnerability occurring within the runtime.macClone function. Because the vulnerability is reachable via the mc.ip parameter without requiring authentication, it allows for remote code execution.

Business impact

Successful exploitation grants an attacker complete control over the affected router, potentially leading to unauthorized network access, interception of traffic, and the use of the device as a pivot point for lateral movement into the internal network. With a CVSS score of 9.8, the impact is considered critical due to the ease of remote exploitation and the potential for total system compromise.

Remediation

Immediate Action: As no specific patch version is currently identified, isolate the affected E5600 devices from the internet or disable the vulnerable MAC clone feature if possible until the vendor releases a firmware update.

Proactive Monitoring: Monitor network traffic for unusual outbound connections or shell-related patterns originating from the router's management interface.

Compensating Controls: Ensure the router is behind a firewall that restricts management access to trusted internal IP addresses only.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical CVSS severity and the existence of a proof-of-concept, users should treat this vulnerability with extreme urgency. Immediately restrict access to the device management interface and monitor vendor channels for the release of a patched firmware version.

More Linksys CVEs