PT-2026-27013 · Linksys · Linksys Mr9600
Vuldb
+1
·
Published
2026-03-22
·
Updated
2026-03-23
·
CVE-2026-4558
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linksys MR9600 version 2.0.6.206937
Description
A flaw exists in the Linksys MR9600 firmware. The
smartConnectConfigure function within the SmartConnect.lua file is susceptible to operating system command injection. Manipulation of the arguments configApSsid, configApPassphrase, srpLogin, and srpPassword can lead to unauthorized command execution. The issue is remotely exploitable. Reports indicate the exploit has been published and is potentially being used in attacks. The vendor was notified but did not respond.Recommendations
Linksys MR9600 version 2.0.6.206937: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linksys Mr9600