CVE-2026-25603

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys MX4200 allows that contents of a USB drive partition can be mounted in an arbitrary location of the file system. This may result in the execution of shell scripts in the context of a root user.This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:linksys:mr9600_firmware:1.0.4.205530:*:*:*:*:*:*:*
cpe:2.3:h:linksys:mr9600:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:linksys:mx4200_firmware:1.0.4.205530:*:*:*:*:*:*:*
cpe:2.3:h:linksys:mx4200:-:*:*:*:*:*:*:*

History

17 Jun 2026, 10:24

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de Limitación Inadecuada de un Nombre de Ruta a un Directorio Restringido ('Salto de Ruta') en Linksys MR9600, Linksys MX4200 permite que el contenido de una partición de unidad USB pueda montarse en una ubicación arbitraria del sistema de archivos. Esto puede resultar en la ejecución de scripts de shell en el contexto de un usuario root. Este problema afecta a MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

26 Feb 2026, 18:10

Type Values Removed Values Added
CPE cpe:2.3:o:linksys:mx4200_firmware:1.0.4.205530:*:*:*:*:*:*:*
cpe:2.3:o:linksys:mr9600_firmware:1.0.4.205530:*:*:*:*:*:*:*
cpe:2.3:h:linksys:mr9600:-:*:*:*:*:*:*:*
cpe:2.3:h:linksys:mx4200:-:*:*:*:*:*:*:*
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-001.txt - () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-001.txt - Exploit, Third Party Advisory
First Time Linksys mr9600 Firmware
Linksys mx4200
Linksys
Linksys mx4200 Firmware
Linksys mr9600

24 Feb 2026, 19:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.6

24 Feb 2026, 18:29

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-24 18:29

Updated : 2026-06-17 10:24


NVD link : CVE-2026-25603

Mitre link : CVE-2026-25603

CVE.ORG link : CVE-2026-25603


JSON object : View

Products Affected

linksys

  • mr9600
  • mr9600_firmware
  • mx4200
  • mx4200_firmware
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')