CVE-2026-27850
7.5Linksys · MR9600, MX4200
A firewall configuration error in Linksys routers allows unauthenticated remote attackers to bypass network restrictions by initiating connections from source port 5222 on the WAN interface.
Executive summary
An improperly configured firewall rule in Linksys MR9600 and MX4200 routers exposes local network services to the internet, creating a significant risk of unauthorized access and remote command injection.
Vulnerability
The device contains an iptables firewall rule that explicitly accepts incoming traffic on the WAN port if the source port is set to 5222. This allows unauthenticated attackers to interact with services typically restricted to the local network, potentially facilitating further exploitation like OS command injection.
Business impact
The exposure of internal services to the public internet significantly increases the attack surface of the home or small office network. Successful exploitation could lead to full device compromise, unauthorized access to sensitive data, or the use of the router as a pivot point for lateral movement within the network. With a CVSS score of 7.5, this high severity vulnerability warrants immediate attention to prevent unauthorized administrative control.
Remediation
Immediate Action: Update the firmware for the Linksys MX4200 to version 1.0.13.216602 or the latest available version provided by Linksys for your specific model.
Proactive Monitoring: Monitor firewall and system logs for incoming connection attempts originating from source port 5222 on the WAN interface.
Compensating Controls: If a patch cannot be applied immediately, ensure that no sensitive services are exposed to the router management interface and consider placing the device behind a secondary firewall or disabling remote management features.
Exploitation status
Public Exploit Available: Yes, a published proof of concept exists, as documented in the SySS security advisory.
Analyst recommendation
Given the availability of a public proof of concept and the potential for remote command injection, users must prioritize firmware updates for affected Linksys hardware. Failure to patch these devices leaves the local network vulnerable to external attackers who can bypass perimeter defenses through this specific firewall misconfiguration. Please verify your current firmware version and apply the manufacturer update as soon as possible.