High-severity vulnerabilities have been disclosed in two consumer router lines, enabling remote operating system command injection through web-facing configuration functions. CVE-2026-4558 affects the Linksys MR9600 running firmware 2.0.6.206937, where the smartConnectConfigure function in SmartConnect.lua can be abused by manipulating configApSsid, configApPassphrase, srpLogin, or srpPassword. The flaw is classified under CWE-78 and CWE-77, carries high impact to confidentiality, integrity, and availability, and the disclosure says a public exploit exists and may already be used in the wild. The report also states that Linksys was contacted before publication but did not respond.
A separate issue, CVE-2026-4611, affects TOTOLINK X6000R devices on firmware 9.4.0cu.1360_B20241207 and 9.4.0cu.1498_B20250826. In that case, the setLanCfg function within /usr/sbin/shttpd allows remote command injection via the Hostname argument, creating a path to privilege escalation and full device compromise. Like the Linksys flaw, the TOTOLINK bug is mapped to CWE-78 and CWE-77 and is rated high severity across published scoring, underscoring continued risk from insecure input handling in router administration components.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A remote OS command injection vulnerability in the setLanCfg function of /usr/sbin/shttpd was recorded for TOTOLINK X6000R firmware versions 9.4.0cu.1360_B20241207 and 9.4.0cu.1498_B20250826. The issue, triggered through the Hostname argument, was received by cna@vuldb.com and published with high-severity impact ratings.
A vulnerability affecting Linksys MR9600 firmware 2.0.6.206937 was disclosed, involving OS command injection in the SmartConnect.lua smartConnectConfigure function via parameters including configApSsid, configApPassphrase, srpLogin, and srpPassword. The disclosure noted high impact and said an exploit had been published, while also stating Linksys had been contacted earlier but did not respond.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceopenwrt.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.