CVE-2026-27849: Missing neutralization in Linksys MR9600, Linksys MX4200
Published Feb 25, 2026
·Updated
Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP connection, which is normally used for configuring devices inside the mesh network. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.
Affected Software
2 affected components
LinkSys MR9600
LinkSys MX4200
Event History
Feb 25, 2026
CVE Published
via MITRE·04:20 PM
Data Sourced
via MITRE·04:20 PM
DescriptionWeakness
Data Sourced
via NVD·05:25 PM
DescriptionSeverityWeakness
Oct 1, 58139
Event
via FIRST·08:18 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-27849?
CVE-2026-27849 is rated as a medium severity vulnerability due to the risk of OS command injection.
2
How do I fix CVE-2026-27849?
To fix CVE-2026-27849, update your Linksys MR9600 or Linksys MX4200 devices to the latest firmware version provided by Linksys.
3
What devices are affected by CVE-2026-27849?
CVE-2026-27849 affects Linksys MR9600 and Linksys MX4200 models.
4
What types of attacks can CVE-2026-27849 facilitate?
CVE-2026-27849 can facilitate OS command injection attacks through the update functionality.
5
Is CVE-2026-27849 being actively exploited?
As of now, there have been no reports of active exploitation of CVE-2026-27849.