🔐 CVE Alert

CVE-2026-25603

MEDIUM 6.6

Path Traversal vulnerability in Linksys MR9600, Linksys MX4200

CVSS Score
6.6
EPSS Score
0.0%
EPSS Percentile
0th

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys MX4200 allows that contents of a USB drive partition can be mounted in an arbitrary location of the file system. This may result in the execution of shell scripts in the context of a root user.This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

CWE CWE-22
Vendor linksys
Product mr9600
Published Feb 24, 2026
Last Updated Feb 24, 2026
Stay Ahead of the Next One

Get instant alerts for linksys mr9600

Be the first to know when new medium vulnerabilities affecting linksys mr9600 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Linksys / MR9600
1.0.4.205530
Linksys / MX4200
1.0.13.210200

References

NVD ↗ CVE.org ↗ EPSS Data ↗
syss.de: https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-001.txt