CVE-2026-27850: Improper verification in Linksys MR9600, Linksys MX4200
Due to an improperly configured firewall rule, the router will accept any connection on the WAN port with the source port 5222, exposing all services which are normally only accessible through the local network. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.
Affected Software
Event History
Frequently Asked Questions
What devices are affected by CVE-2026-27850?
CVE-2026-27850 affects Linksys MR9600 and Linksys MX4200 routers.
What is the severity of CVE-2026-27850?
CVE-2026-27850 is considered a critical vulnerability due to improper firewall configurations.
How do I fix CVE-2026-27850?
To fix CVE-2026-27850, review and update your firewall settings to block unwanted access on the WAN port.
What are the risks associated with CVE-2026-27850?
CVE-2026-27850 may expose sensitive services normally restricted to the local network, increasing the risk of unauthorized access.
How does CVE-2026-27850 impact router security?
CVE-2026-27850 compromises router security by allowing connections on the WAN port, potentially leading to data breaches.