CVE-2026-27847: Missing authentication in Linksys MR9600, Linksys MX4200
Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connection. This can be used to inject known credentials into the database that can be utilized to successfully complete the handshake and use the protected service. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27847?
CVE-2026-27847 has been rated as a high-severity vulnerability due to the potential for SQL injection.
How do I fix CVE-2026-27847?
To fix CVE-2026-27847, it is recommended to apply any available security patches provided by Linksys for the affected devices.
What devices are affected by CVE-2026-27847?
The affected devices for CVE-2026-27847 include the Linksys MR9600 and Linksys MX4200.
Can CVE-2026-27847 be exploited remotely?
Yes, CVE-2026-27847 can be exploited remotely, allowing attackers to potentially gain unauthorized access to the database.
What impact does CVE-2026-27847 have on data security?
CVE-2026-27847 can lead to unauthorized data manipulation and access, exposing sensitive user information and compromising database integrity.