Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Wuuu

#14947of 53,630
18Total CVSS
Vulnerabilities · 2
High
2
PT-2026-35165
9.0
2026-04-25
Linksys · Mr9600 · CVE-2026-6992
**Name of the Vulnerable Software and Affected Versions** Linksys MR9600 version 2.0.6.206937 **Description** An OS command injection issue exists in the JNAP Action Handler component. The `BTRequestGetSmartConnectStatus()` function within the `/etc/init.d/run central2.sh` file fails to neutralize special elements in the `pin` argument. This allows a remote attacker to execute arbitrary code on the device. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-27013
9.0
2026-03-22
Linksys · Linksys Mr9600 · CVE-2026-4558
**Name of the Vulnerable Software and Affected Versions** Linksys MR9600 version 2.0.6.206937 **Description** A flaw exists in the Linksys MR9600 firmware. The `smartConnectConfigure` function within the `SmartConnect.lua` file is susceptible to operating system command injection. Manipulation of the arguments `configApSsid`, `configApPassphrase`, `srpLogin`, and `srpPassword` can lead to unauthorized command execution. The issue is remotely exploitable. Reports indicate the exploit has been published and is potentially being used in attacks. The vendor was notified but did not respond. **Recommendations** Linksys MR9600 version 2.0.6.206937: At the moment, there is no information about a newer version that contains a fix for this vulnerability.