Executive brief
A security vulnerability has been identified in Cudy TR1200 and TR3000 routers, which are devices used to provide internet connectivity and manage home or office networks. An attacker can exploit this flaw to take complete control of the router by executing unauthorized commands with the highest level of system privileges. This could lead to the interception of network traffic, theft of sensitive data, or a total disruption of internet services.
Technical details
A command injection vulnerability exists in the 'system.setclock' interface of Cudy TR1200 (v2.4.15) and TR3000 (v2.4.21) routers. The flaw stems from insufficient sanitization of user-supplied input passed to system-level commands responsible for setting the device clock. An unauthenticated remote attacker can exploit this by sending a specially crafted request to the affected interface, leading to arbitrary command execution with root privileges. This allows for full system compromise, including persistent access and lateral movement within the local network.
Affected products
- Cudy TR1200 v2.4.15
- Cudy TR3000 v2.4.21
Timeline
- 2026-07-31: disclosed
- 2026-07-31: advisory