Linksys E5600 Command Injection Vulnerability in DDNS Status Function

Vulnerability

A command injection vulnerability has been identified in the Linksys E5600 router, specifically in firmware version V1.1.0.26. The issue arises in the 'ddnsStatus' function, where user-supplied data can be manipulated to execute arbitrary commands on the device.

Impact

Exploitation of this vulnerability allows for command injection, where an attacker can execute arbitrary commands on the router's operating system.

Reproduction

To reproduce this vulnerability, log into the router and send a POST request to the '/API/obj' endpoint with crafted JSON data that includes the 'ddns' object. The 'username', 'password', and 'hostname' fields can be used to inject commands. After the injection, send a POST request to the '/API/info' endpoint to retrieve the output of the executed commands.

Added: Dec 23, 2025, 5:24 PM
Updated: Dec 23, 2025, 5:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.6
remediation
0.0
relevance
1.6
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.