CVE-2026-27848: Missing neutralization in Linksys MR9600, Linksys MX4200
Due to missing neutralization of special elements, OS commands can be injected via the handshake of a TLS-SRP connection, which are ultimately run as the root user. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27848?
CVE-2026-27848 is considered a critical vulnerability due to the potential for OS command injection as the root user.
How do I fix CVE-2026-27848?
To remediate CVE-2026-27848, apply the latest firmware update provided by Linksys for the MR9600 and MX4200 devices.
Which devices are affected by CVE-2026-27848?
CVE-2026-27848 affects the Linksys MR9600 running version 1.0.4.205530 and the Linksys MX4200 running version 1.0.13.210200.
What type of issue is CVE-2026-27848?
CVE-2026-27848 is a security vulnerability that involves missing neutralization, allowing for command injection during the TLS-SRP handshake.
Can CVE-2026-27848 lead to unauthorized access?
Yes, CVE-2026-27848 can lead to unauthorized access and control of affected devices due to command execution as the root user.