CVE-2026-27848 Details
Description
Due to missing neutralization of special elements, OS commands can be injected via the handshake of a TLS-SRP connection, which are ultimately run as the root user. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.
A command injection vulnerability has been identified in the Linksys MR9600 and MX4200 routers, specifically in versions 1.0.4.205530 and 1.0.13.210200, respectively. The issue arises from the 'sct_server' service, which runs on TCP port 6060. This service, used for integrating mesh devices into the network, accepts TLS-SRP connections but fails to properly sanitize input. As a result, OS commands can be injected through the username field of the TLS-SRP handshake. These commands are executed with root privileges, without requiring a valid username or password.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 25, 2026CISA-ADP
Assessed Feb 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-010.txt | ENISA | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | ENISA |
Affected Products
| Product | Versions |
|---|---|
| Linksys MR9600 | 1.0.4.205530 |
CPE
Remediation
| |
| Linksys MX4200 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ENISA |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 26, 2026 | CVE Modified | CISA-ADP |
| Feb 25, 2026 | New CVE Received | ENISA |
Volerion