PT-2026-21778 · Linksys · Linksys Mr9600+1

Christian Zä​Ske

·

Published

2026-02-24

·

Updated

2026-02-26

·

CVE-2026-25603

CVSS v3.1

6.6

Medium

VectorAV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linksys MR9600 version 1.0.4.205530 Linksys MX4200 version 1.0.13.210200
Description A path traversal issue exists in Linksys MR9600 and MX4200 devices. This allows the contents of a USB drive partition to be mounted in an arbitrary location within the file system. Successful exploitation may lead to the execution of shell scripts with root privileges.
Recommendations Linksys MR9600 version 1.0.4.205530: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Linksys MX4200 version 1.0.13.210200: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-25603

Affected Products

Linksys Mr9600
Linksys Mx4200