« Back to list

CVE-2026-27847

Status: DeferredCritical (9.8)—

Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connection. This can be used to inject known credentials into the database that can be utilized to successfully complete the handshake and use the protected service. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

SQL injection (CWE-89) en servicio de red sin autenticación previa (AV:N/PR:N/UI:N) permite lectura de datos y manipulación de credenciales en BD para acceso no autorizado.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (2)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-27847",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-27847",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-02-26T16:55:30.669110Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
      "affectedData": [
        {
          "vendor": "Linksys",
          "product": "MR9600",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.4.205530"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Linksys",
          "product": "MX4200",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.13.210200"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-02-25T16:23:28.833",
  "references": [
    {
      "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-009.txt",
      "source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connection. This can be used to inject known credentials into the database that can be utilized to successfully complete the handshake and use the protected service.\nThis issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200."
    },
    {
      "lang": "es",
      "value": "Debido a la neutralización inadecuada de elementos especiales, se pueden inyectar sentencias SQL a través del handshake de una conexión TLS-SRP. Esto puede ser utilizado para inyectar credenciales conocidas en la base de datos que pueden ser utilizadas para completar exitosamente el handshake y usar el servicio protegido.\nEste problema afecta a MR9600: 1.0.4.205530; MX4200: 1.0.13.210200."
    }
  ],
  "lastModified": "2026-06-17T10:27:47.093",
  "sourceIdentifier": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
}