CVE-2026-27846 Details
Description
Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a new mesh device to the network to gain access to sensitive information, including the password for admin access to the web interface and the Wi-Fi passwords.This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.
A vulnerability exists in the Linksys MR9600 (firmware 1.0.4.205530) and MX4200 (firmware 1.0.13.210200) routers, allowing a user with physical access to the device to exploit the mesh functionality. This exploitation can lead to unauthorized access to sensitive information, such as the admin password for the web interface and Wi-Fi passwords. The issue arises from missing authentication in the mesh device-adding process, which can be manipulated to retrieve confidential data.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 25, 2026CISA-ADP
Assessed Feb 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-002.txt | ENISA | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | ENISA |
Affected Products
| Product | Versions |
|---|---|
| Linksys MR9600 | 1.0.4.205530 |
CPE
Remediation
| |
| Linksys MX4200 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ENISA |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 25, 2026 | CVE Modified | CISA-ADP |
| Feb 25, 2026 | New CVE Received | ENISA |
Volerion