CVE-2026-27848 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: February 27, 2026
MR9600 & MX4200 - Command Injection
Published: February 25, 2026Updated: February 27, 2026Remote Exploitable
Overview
MR9600 1.0.4.205530 and MX4200 1.0.13.210200 contain a command injection caused by missing neutralization of special elements in TLS-SRP handshake, letting attackers execute OS commands as root, exploit requires network access to initiate TLS-SRP handshake.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Attackers can execute OS commands as root, leading to full system compromise.
Mitigation
Update to the latest available versions beyond 1.0.4.205530 for MR9600 and 1.0.13.210200 for MX4200.
Related Resources
Details
- CVE ID
- CVE-2026-27848
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- command_injection
- Status
- unconfirmed
CWE
- CWE-78
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H