Path Traversal Vulnerability in Linksys MR9600 and MX4200
CVE-2026-25603
What is CVE-2026-25603?
A path traversal vulnerability in Linksys MR9600 and MX4200 routers allows for improper limitation of a pathname to a restricted directory. This flaw results in the possibility to mount the contents of a USB drive partition at arbitrary locations within the file system. Consequently, this could lead to the execution of shell scripts with escalated privileges, posing a significant security risk for users. It is essential for owners of these devices to implement the necessary updates to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MR9600 1.0.4.205530
MX4200 1.0.13.210200
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved