CVE-2026-25603: Linksys MR9600 Firmware
Medium severity, CVSS 6.6. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys MX4200 allows that contents of a USB drive partition can be mounted in an arbitrary location of the file system. This may result in the execution of shell scripts in the context of a root user.This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.
Affected products
- Linksys MR9600 Firmware: version 1.0.4.205530 only
- Linksys MX4200 Firmware: version 1.0.4.205530 only
Published 2026-02-24. Last modified 2026-06-17.