Junglewise Threat Intelligence

CVE-2026-38709: Cudy Routers command injection in net.set_wan interface

CVE-2026-38709 · Severity: info · CVSS 9.8 · Published 2026-07-30

Executive brief

Multiple Cudy router models contain a security flaw in their network configuration interface. This vulnerability allows an attacker to take complete control of the router by executing unauthorized commands with the highest level of system privileges (root). A successful exploit could lead to the interception of internet traffic, unauthorized access to the local network, or a complete shutdown of the device.

Technical details

A command injection vulnerability exists in the 'net.set_wan' interface of several Cudy router models. The flaw is caused by insufficient sanitization of user-supplied input before it is passed to a system shell. An attacker can exploit this by sending a specially crafted request to the affected interface, leading to arbitrary code execution with root privileges. The vulnerability affects multiple firmware versions across the TR1200, TR3000, WR300, WR1200, WR1300, WR1500, WR3000, WR3600, and WR6500 product lines. Users are advised to check for firmware updates from the vendor.

Affected products

  • Cudy TR1200 v2.4.15
  • Cudy TR3000 v2.4.21
  • Cudy WR300 v2.4.25
  • Cudy WR1200 v2.4.23
  • Cudy WR1300 v2.4.22
  • Cudy WR1500 v2.3.10
  • Cudy WR3000 v2.4.19
  • Cudy WR3600 v2.3.16
  • Cudy WR6500 v2.3.15

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory

References

Related threats