Linksys E5600 Command Injection Vulnerability in the Runtime.macClone Function

Vulnerability

A command injection vulnerability has been identified in the Linksys E5600 router, specifically in firmware version V1.1.0.26. The issue arises within the runtime.macClone function, where the mc.ip parameter can be manipulated to inject and execute arbitrary commands.

Impact

Exploitation of this vulnerability allows for command injection, where an attacker can execute arbitrary commands on the device.

Reproduction

To reproduce this vulnerability, send a request to the Linksys E5600 router's runtime.macClone function, including a crafted mc.ip parameter that contains the desired command injection payload. For example, injecting a command like 'ping -c 3 192.168.10.128' through the mc.ip parameter will demonstrate the command injection by executing the ping command and returning the results.

Added: Dec 23, 2025, 5:24 PM
Updated: Dec 23, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.7
remediation
0.0
relevance
1.7
threat
6.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.