VYPR

MR9600

by Linksys

CVEs (6)

  • CVE-2026-27849CriFeb 25, 2026
    risk 0.64cvss 9.8epss 0.00

    Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP connection, which is normally used for configuring devices inside the mesh network. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

  • CVE-2026-4558HigMar 22, 2026
    risk 0.58cvss 8.8epss 0.05

    A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipulation of the argument configApSsid/configApPassphrase/srpLogin/srpPassword can lead to os command injection. The attack may be…

  • CVE-2026-6992HigApr 25, 2026
    risk 0.47cvss 7.2epss 0.06

    A vulnerability was identified in Linksys MR9600 2.0.6.206937. This affects the function BTRequestGetSmartConnectStatus of the file /etc/init.d/run_central2.sh of the component JNAP Action Handler. The manipulation of the argument pin leads to os command injection. The attack…

  • CVE-2026-25603MedFeb 24, 2026
    risk 0.43cvss 6.6epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys MX4200 allows that contents of a USB drive partition can be mounted in an arbitrary location of the file system. This may result in the execution of shell…

  • CVE-2026-27846MedFeb 25, 2026
    risk 0.40cvss 6.2epss 0.00

    Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a new mesh device to the network  to gain access to sensitive information, including the password for admin access to the web interface and the Wi-Fi…

  • CVE-2022-24372MedApr 27, 2022
    risk 0.30cvss 4.6epss 0.00

    Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of a NAS SMB share.