VYPR
Unrated severityNVD Advisory· Published Feb 24, 2026· Updated Feb 24, 2026

Path Traversal vulnerability in Linksys MR9600, Linksys MX4200

CVE-2026-25603

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys MX4200 allows that contents of a USB drive partition can be mounted in an arbitrary location of the file system. This may result in the execution of shell scripts in the context of a root user.This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

Affected products

4
  • Linksys/MX4200llm-create
    Range: <= 1.0.13.210200
  • Linksys/MR9600llm-fuzzy
    Range: <= 1.0.4.205530
  • Linksys/MR9600v5
    Range: 1.0.4.205530
  • Linksys/MX4200v5
    Range: 1.0.13.210200

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.