Executive brief
Multiple Cudy router models contain a security flaw in the system clock management interface. This vulnerability allows an attacker to take complete control of the device by executing unauthorized commands with the highest level of administrative privileges (root). A successful exploit could lead to the interception of internet traffic, unauthorized access to the local network, or a total disruption of service.
Technical details
A command injection vulnerability exists in the 'system.setclock' interface of several Cudy router models. The flaw stems from insufficient sanitization of user-supplied input before it is passed to a system shell for execution. An attacker can exploit this by sending specially crafted requests to the interface to execute arbitrary shell commands with root privileges. The vulnerability affects multiple firmware versions across the TR1200, TR3000, WR300, WR1200, WR1300, WR1500, WR3000, WR3600, and WR6500 product lines.
Affected products
- Cudy TR1200 2.4.15
- Cudy TR3000 2.4.21
- Cudy WR300 2.4.25
- Cudy WR1200 2.4.23
- Cudy WR1300 2.4.22
- Cudy WR1500 2.3.10
- Cudy WR3000 2.4.19
- Cudy WR3600 2.3.16
- Cudy WR6500 2.3.15
Timeline
- 2026-07-31: disclosed
- 2026-07-31: advisory