CVE-2026-27847 PUBLISHED

Missing authentication in Linksys MR9600, Linksys MX4200

Assigner: ENISA
Reserved: 24.02.2026 Published: 25.02.2026 Updated: 25.02.2026

Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connection. This can be used to inject known credentials into the database that can be utilized to successfully complete the handshake and use the protected service. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

Product Status

Vendor Linksys
Product MR9600
Versions Default: affected
  • Version 1.0.4.205530 is affected
Vendor Linksys
Product MX4200
Versions Default: unaffected
  • Version 1.0.13.210200 is affected

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE