Description
A vulnerability was identified in Linksys MR9600 2.0.6.206937. This affects the function BTRequestGetSmartConnectStatus of the file /etc/init.d/run_central2.sh of the component JNAP Action Handler. The manipulation of the argument pin leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-04-25
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: remote command execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an OS command injection in the BTRequestGetSmartConnectStatus action of the JNAP Action Handler on the Linksys MR9600 router. By supplying a specially crafted pin argument, an attacker can inject arbitrary system commands that are executed with the privileges of the router’s firmware. This allows remote attackers to compromise the entire device, gaining full control over the system, exfiltrating data, installing malware, or disrupting network operation.

Affected Systems

The flaw affects the Linksys MR9600, specifically firmware 2.0.6.206937. Other firmware variants may also be susceptible if they include the same vulnerable /etc/init.d/run_central2.sh script. Because the vulnerability resides in the router's JNAP interface, any device accessed through that interface could be impacted.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, and the EPSS score of less than 1% suggests a low probability of widespread exploitation in the short term. However, the exploit code is publicly available, and there is no known mitigation in CISA KEV. The attack is remote and can be launched over the network by sending a request to the JNAP endpoint that triggers the vulnerable action, making it highly actionable to attackers with network visibility to the device.

Generated by OpenCVE AI on April 28, 2026 at 05:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update available from Linksys that addresses the command injection.
  • If a firmware update is not yet released, restrict or disable the JNAP interface or the BTRequestGetSmartConnectStatus action via router settings or firewall rules.
  • Monitor device logs for suspicious JNAP activity and enforce network segmentation around the router to limit potential lateral movement.

Generated by OpenCVE AI on April 28, 2026 at 05:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:h:linksys:mr9600:-:*:*:*:*:*:*:*
cpe:2.3:o:linksys:mr9600_firmware:2.0.6.206937:*:*:*:*:*:*:*

Mon, 27 Apr 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Linksys mr9600
Vendors & Products Linksys mr9600

Mon, 27 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 25 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Linksys MR9600 2.0.6.206937. This affects the function BTRequestGetSmartConnectStatus of the file /etc/init.d/run_central2.sh of the component JNAP Action Handler. The manipulation of the argument pin leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Linksys MR9600 JNAP Action run_central2.sh BTRequestGetSmartConnectStatus os command injection
First Time appeared Linksys
Linksys mr9600 Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:linksys:mr9600_firmware:*:*:*:*:*:*:*:*
Vendors & Products Linksys
Linksys mr9600 Firmware
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Linksys Mr9600 Mr9600 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-27T13:34:09.962Z

Reserved: 2026-04-24T19:39:58.219Z

Link: CVE-2026-6992

cve-icon Vulnrichment

Updated: 2026-04-27T13:10:56.743Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-25T18:16:19.413

Modified: 2026-04-30T14:09:56.830

Link: CVE-2026-6992

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T05:45:23Z

Weaknesses