Linksys MR9600
cpe:2.3:h:linksys:mr9600:*:*:*:*:*:*:*
- 1.0.4.205530
A command injection vulnerability has been identified in the Linksys MR9600 and MX4200 routers, specifically in the update functionality of a TLS-SRP connection used for device configuration within the mesh network. This vulnerability arises from inadequate sanitization of input, allowing OS commands to be injected and executed on the device.
Exploitation of this vulnerability allows for arbitrary OS command execution on the affected device.
The vulnerability can be reproduced by sending a crafted update request through a TLS-SRP connection to the device's service running on TCP port 6060. The injected command can be verified by observing the device's LED indicator, which will change color to indicate successful execution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.