Impact
The vulnerability is an OS command injection in the BTRequestGetSmartConnectStatus action of the JNAP Action Handler on the Linksys MR9600 router. By supplying a specially crafted pin argument, an attacker can inject arbitrary system commands that are executed with the privileges of the router’s firmware. This allows remote attackers to compromise the entire device, gaining full control over the system, exfiltrating data, installing malware, or disrupting network operation.
Affected Systems
The flaw affects the Linksys MR9600, specifically firmware 2.0.6.206937. Other firmware variants may also be susceptible if they include the same vulnerable /etc/init.d/run_central2.sh script. Because the vulnerability resides in the router's JNAP interface, any device accessed through that interface could be impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and the EPSS score of less than 1% suggests a low probability of widespread exploitation in the short term. However, the exploit code is publicly available, and there is no known mitigation in CISA KEV. The attack is remote and can be launched over the network by sending a request to the JNAP endpoint that triggers the vulnerable action, making it highly actionable to attackers with network visibility to the device.
OpenCVE Enrichment