CVE-2026-25603: Path Traversal vulnerability in Linksys MR9600, Linksys MX4200
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys MX4200 allows that contents of a USB drive partition can be mounted in an arbitrary location of the file system. This may result in the execution of shell scripts in the context of a root user.This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25603?
CVE-2026-25603 has been classified with a high severity due to the potential for remote code execution.
How do I fix CVE-2026-25603?
To fix CVE-2026-25603, it is recommended to apply the latest firmware updates from Linksys for the MR9600 and MX4200 models.
What systems are affected by CVE-2026-25603?
CVE-2026-25603 affects the Linksys MR9600 and Linksys MX4200 routers.
What types of attacks can be executed through CVE-2026-25603?
CVE-2026-25603 may allow attackers to execute arbitrary shell scripts due to improper limitation of pathname access.
Is CVE-2026-25603 easily exploitable?
Yes, due to its nature, CVE-2026-25603 can be easily exploited if proper safeguards are not in place.