CVE-2026-27846: Missing authentication in Linksys MR9600, Linksys MX4200
Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a new mesh device to the network to gain access to sensitive information, including the password for admin access to the web interface and the Wi-Fi passwords.This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27846?
CVE-2026-27846 is considered a high-severity vulnerability due to its potential to allow unauthorized access to sensitive information.
How do I fix CVE-2026-27846?
To mitigate CVE-2026-27846, ensure physical security measures are in place to limit unauthorized access to the Linksys MR9600 and Linksys MX4200 devices.
What types of devices are affected by CVE-2026-27846?
CVE-2026-27846 affects Linksys MR9600 and Linksys MX4200 models.
What information can be compromised due to CVE-2026-27846?
CVE-2026-27846 can lead to access to sensitive information, including the admin web access password.
Is remote access affected by CVE-2026-27846?
CVE-2026-27846 specifically pertains to physical access, and does not directly impact remote access capabilities.