CVE-2026-27850: Linksys MR9600

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Due to an improperly configured firewall rule, the router will accept any connection on the WAN port with the source port 5222, exposing all services which are normally only accessible through the local network. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

Affected products

  • Linksys MR9600: version 1.0.4.205530 only
  • Linksys MX4200: version 1.0.13.210200 only

Published 2026-02-25. Last modified 2026-06-17.