Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.2

Physical Access to Device Allows Unauthorized Network Access

CVE-2026-27846
Summary

A user with physical access to the device can add a new mesh device to the network without permission, potentially gaining access to sensitive information like admin passwords and Wi-Fi credentials. This could lead to unauthorized access to your network and sensitive data. Update your device to the latest firmware to fix this issue.

Original title
Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a new mesh device to the network  to gain access to sensitive information, incl...
Original description
Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a new mesh device to the network 
to gain access to sensitive information, including the password for admin access to the web interface and the Wi-Fi passwords.This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.
nvd CVSS3.1 6.2
Vulnerability type
CWE-306 Missing Authentication for Critical Function
Published: 25 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026