Impact
The vulnerability is an OS command injection that comes from the BTRequestGetSmartConnectStatus action in the JNAP Action Handler on a Linksys MR9600 router. By supplying a crafted pin argument, an attacker can execute arbitrary system commands with the privileges of the router’s firmware, resulting in full control over the device, the ability to exfiltrate data, install malware, or disrupt network operations. This falls under CWE-77 and CWE-78.
Affected Systems
The flaw affects the Linksys MR9600 with firmware 2.0.6.206937, as identified in the /etc/init.d/run_central2.sh script. Based on the description, it is inferred that other firmware versions that include the same vulnerable script may also be susceptible, but no explicit confirmation is provided in the CVE data.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and the EPSS score of 7% suggests a moderate likelihood of exploitation. The vulnerability is available for remote exploitation via the JNAP interface, and an exploit code is publicly available. The vulnerability is not listed in CISA’s KEV catalog, but the lack of a public mitigation does not reduce the risk posed to affected devices.
OpenCVE Enrichment