CVE-2026-4558
- EPSS 0.15%
- Veröffentlicht 22.03.2026 17:29:35
- Zuletzt bearbeitet 23.03.2026 14:31:37
A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipulation of the argument configApSsid/configApPassphrase/srpLogin/srpPassword can lead to os command in...
CVE-2026-27850
- EPSS 0.04%
- Veröffentlicht 25.02.2026 16:58:06
- Zuletzt bearbeitet 27.02.2026 14:06:59
Due to an improperly configured firewall rule, the router will accept any connection on the WAN port with the source port 5222, exposing all services which are normally only accessible through the local network. This issue affects MR9600: 1.0.4.20553...
CVE-2026-27849
- EPSS 0.06%
- Veröffentlicht 25.02.2026 16:20:25
- Zuletzt bearbeitet 27.02.2026 14:06:59
Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP connection, which is normally used for configuring devices inside the mesh network. This issue affects MR9600: 1.0.4.205530; MX42...
CVE-2026-27848
- EPSS 0.06%
- Veröffentlicht 25.02.2026 15:15:16
- Zuletzt bearbeitet 27.02.2026 14:06:59
Due to missing neutralization of special elements, OS commands can be injected via the handshake of a TLS-SRP connection, which are ultimately run as the root user. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.
CVE-2026-27847
- EPSS 0.06%
- Veröffentlicht 25.02.2026 15:10:30
- Zuletzt bearbeitet 27.02.2026 14:06:59
Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connection. This can be used to inject known credentials into the database that can be utilized to successfully complete the handshake a...
CVE-2026-27846
- EPSS 0.02%
- Veröffentlicht 25.02.2026 15:03:58
- Zuletzt bearbeitet 27.02.2026 14:06:59
Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a new mesh device to the network to gain access to sensitive information, including the password for admin access to the web interf...
CVE-2026-25603
- EPSS 0.02%
- Veröffentlicht 24.02.2026 17:14:36
- Zuletzt bearbeitet 26.02.2026 18:10:54
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys MX4200 allows that contents of a USB drive partition can be mounted in an arbitrary location of the file system. This may result i...