Linksys MR9600 Command Injection Vulnerability in JNAP Action Handler

Vulnerability

A command injection vulnerability has been identified in the Linksys MR9600 router, specifically in the firmware version 2.0.6.206937. The issue arises within the JNAP Action Handler, in a function called BTRequestGetSmartConnectStatus. The vulnerability is triggered by manipulating the 'pin' argument, which is passed to a Bluetooth management function and then concatenated into a shell command executed by the router's operating system. This flaw allows authenticated attackers to inject arbitrary commands that are executed with root privileges.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device, with root privileges.

Reproduction

To reproduce this vulnerability, first set the device to 'Master' mode. Once in the correct mode, send a request to the JNAP action 'BTRequestGetSmartConnectStatus' with a crafted 'pin' parameter that includes a command injection payload. The injected command will be executed on the device's operating system.

Added: Apr 25, 2026, 6:18 PM
Updated: Apr 25, 2026, 6:18 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
6.2
remediation
0.0
relevance
6.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.