Description
A vulnerability was identified in Linksys MR9600 2.0.6.206937. This affects the function BTRequestGetSmartConnectStatus of the file /etc/init.d/run_central2.sh of the component JNAP Action Handler. The manipulation of the argument pin leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-04-25
Score: 8.6 High
EPSS: 8.1% Low
KEV: No
Impact: Remote command execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an OS command injection that comes from the BTRequestGetSmartConnectStatus action in the JNAP Action Handler on a Linksys MR9600 router. By supplying a crafted pin argument, an attacker can execute arbitrary system commands with the privileges of the router’s firmware, resulting in full control over the device, the ability to exfiltrate data, install malware, or disrupt network operations. This falls under CWE-77 and CWE-78.

Affected Systems

The flaw affects the Linksys MR9600 with firmware 2.0.6.206937, as identified in the /etc/init.d/run_central2.sh script. Based on the description, it is inferred that other firmware versions that include the same vulnerable script may also be susceptible, but no explicit confirmation is provided in the CVE data.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, and the EPSS score of 7% suggests a moderate likelihood of exploitation. The vulnerability is available for remote exploitation via the JNAP interface, and an exploit code is publicly available. The vulnerability is not listed in CISA’s KEV catalog, but the lack of a public mitigation does not reduce the risk posed to affected devices.

Generated by OpenCVE AI on August 30, 2026 at 15:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Linksys that addresses the command injection.
  • If a firmware update is not yet available, restrict or disable the JNAP interface or block the BTRequestGetSmartConnectStatus action using router settings or firewall rules.
  • Monitor device logs for suspicious JNAP activity and enforce network segmentation around the router to limit lateral movement.

Generated by OpenCVE AI on August 30, 2026 at 15:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:h:linksys:mr9600:-:*:*:*:*:*:*:*
cpe:2.3:o:linksys:mr9600_firmware:2.0.6.206937:*:*:*:*:*:*:*

Mon, 27 Apr 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Linksys mr9600
Vendors & Products Linksys mr9600

Mon, 27 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 25 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Linksys MR9600 2.0.6.206937. This affects the function BTRequestGetSmartConnectStatus of the file /etc/init.d/run_central2.sh of the component JNAP Action Handler. The manipulation of the argument pin leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Linksys MR9600 JNAP Action run_central2.sh BTRequestGetSmartConnectStatus os command injection
First Time appeared Linksys
Linksys mr9600 Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:linksys:mr9600_firmware:*:*:*:*:*:*:*:*
Vendors & Products Linksys
Linksys mr9600 Firmware
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Linksys Mr9600 Mr9600 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-27T13:34:09.962Z

Reserved: 2026-04-24T19:39:58.219Z

Link: CVE-2026-6992

cve-icon Vulnrichment

Updated: 2026-04-27T13:10:56.743Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-25T18:16:19.413

Modified: 2026-06-17T11:01:36.490

Link: CVE-2026-6992

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T15:45:04Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')