Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a new mesh device to the network
to gain access to sensitive information, including the password for admin access to the web interface and the Wi-Fi passwords.This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.
References
Configurations
No configuration.
History
25 Feb 2026, 19:43
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.2 |
25 Feb 2026, 16:23
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-25 16:23
Updated : 2026-02-27 14:06
NVD link : CVE-2026-27846
Mitre link : CVE-2026-27846
CVE.ORG link : CVE-2026-27846
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
