🔐 CVE Alert

CVE-2026-27846

MEDIUM 6.2

Missing authentication in Linksys MR9600, Linksys MX4200

CVSS Score
6.2
EPSS Score
0.0%
EPSS Percentile
0th

Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a new mesh device to the network  to gain access to sensitive information, including the password for admin access to the web interface and the Wi-Fi passwords.This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

CWE CWE-306
Vendor linksys
Product mr9600
Published Feb 25, 2026
Last Updated Feb 25, 2026
Stay Ahead of the Next One

Get instant alerts for linksys mr9600

Be the first to know when new medium vulnerabilities affecting linksys mr9600 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Linksys / MR9600
1.0.4.205530
Linksys / MX4200
1.0.13.210200

References

NVD ↗ CVE.org ↗ EPSS Data ↗
syss.de: https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-002.txt