CVE-2026-4558Disclosure(linksys / mr9600)

MEDIUMCVSS 7.4 · HIGH

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch linksys mr9600 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipulation of the argument configApSsid/configApPassphrase/srpLogin/srpPassword can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mr9600
  • mr9600_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 6 mentions (2026-03-22); latest day: 1
  • 9 total mentions across 3 days

Affected systems

Vendors
Products
mr9600mr9600_firmware

2 versions affected across 2 products

Deep dive

Activity timeline9 mentions / 3d
02356Mentions · 2026-03-22: 6Mentions · 2026-03-23: 2Mentions · 2026-06-16: 1PoC Mentioned / Linked · 2026-03-22: 1PoC Mentioned / Linked · 2026-06-16: 1Active Exploitation · 2026-03-22: 1Patch / Workaround · 2026-06-16: 1Technical Details · 2026-03-22: 4Technical Details · 2026-03-23: 103-2203-2306-16
Signal classification5 categories
Disclosure
555.6%
Active Exploitation
111.1%
Exploit
111.1%
General
111.1%
PoC
111.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-226
Active Exploitation1Disclosure4Exploit1
2026-03-232
Disclosure1General1
2026-06-161
PoC1
Full discourse9 posts
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-4558 - Linksys - MR9600 - https://www.redpacketsecurity.com/cve-alert-cve-2026-4558-linksys-mr9600/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4558 #linksys #mr9600

    Post summary

    The post alerts readers to CVE-2026-4558 for the Linksys MR9600 and provides a link to a security advisory, but offers no technical details or additional context.

    0001080
    3.6K followersView on X
  • Israel@f1tym1
    PoC

    윈도우 권한 상승 취약점 GreenPlasma Poc 분석 https://ift.tt/w70kVbP 오늘은 윈도우 권한 상승 취약점인 GreenPlasma Poc 에 대해서 알아보겠습니다. 일단 해당 취약점 패치는 2026년 6월 10일 보안 업데이트 에서 해결된 취약점입니다. GreenPlasma (CVE-2026-4558) 로 … Introduction to Ma…

    Post summary

    The post provides a PoC link for the Windows privilege‑escalation CVE‑2026‑4558, notes that a security update dated June 10, 2026 patches it, but offers no exploit tool details or evidence of active exploitation.

    0000065
    1.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4558 A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipulation of the argum… https://www.cve.org/CVERecord?id=CVE-2026-4558

    Post summary

    A new flaw (CVE-2026-4558) was discovered in Linksys MR9600 firmware, affecting the smartConnectConfigure function in SmartConnect.lua; no PoC, exploit code, active exploitation, or patch details are provided.

    0000087
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4558 - High A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipulation of the argument configApSsid/configA... https://www.thehackerwire.com/vulnerability/CVE-2026-4558/ https://t.co/xkDY3GoHBm

    Post summary

    The tweet provides a brief disclosure of CVE‑2026‑4558 in Linksys MR9600 firmware, detailing the affected function but not including any PoC, exploit, or patch information.

    0000040
    144 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4558 - Linksys MR9600 SmartConnect.lua smartConnectConfigure os command injection Intel Report: https://ift.tt/ib5JjBM

    Post summary

    Alert announces a new command injection vulnerability in Linksys MR9600’s SmartConnect.lua, but provides no PoC, exploit, or patch information.

    0000039
    292 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting Linksys MR9600 (CVE-2026-4558) https://vuldb.com/?ctiid.352385

    Post summary

    CTI finds evidence of ongoing attacks against Linksys MR9600 via CVE-2026-4558, yet no exploit code, patch details, or technical characteristics are disclosed.

    0000077
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4558 Unauthenticated Remote Command Injection in Linksys MR9600 Firmware 2.0.6.206937 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4558

    Post summary

    The notice identifies a newly disclosed unauthenticated remote command injection in Linksys MR9600 firmware, but provides no PoC, exploit code, or remediation details.

    0000040
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-4558: HIGH] Linksys MR9600 2.0.6.206937 found vulnerable to os command injection via smartConnectConfigure function. Exploit public; vendor unresponsive to disclosure.#cve,CVE-2026-4558,#cybersecurity https://cvefind.com/CVE-2026-4558

    Post summary

    The post discloses CVE‑2026‑4558 as an OS command injection flaw in Linksys MR9600, notes a publicly available exploit, but lacks patch information or evidence of active attacks.

    0000062
    605 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Linksys MR9600 (CVE-2026-4558) https://vuldb.com/?id.352385

    Post summary

    The post announces CVE‑2026‑4558 – an important vulnerability in the Linksys MR9600 – and points to a Vuldb database entry for further details.

    0000086
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWlinksysmr9600---
OSlinksysmr9600_firmware2.0.6.206937--

Explore more