Junglewise Threat Intelligence

CVE-2026-38711: Cudy TR and WR Series Routers command injection in system.upgrade_check

CVE-2026-38711 · Severity: info · CVSS 9.8 · Published 2026-07-31

Executive brief

A security vulnerability has been identified in several Cudy router models, which are devices used to provide internet connectivity and manage home or office networks. An attacker could exploit this flaw to take complete control of the router, potentially allowing them to monitor internet traffic, redirect users to malicious websites, or disable the network entirely. This issue is particularly serious because it allows the attacker to gain the highest level of administrative access (root) on the device.

Technical details

A command injection vulnerability exists in the 'system.upgrade_check' interface of multiple Cudy router models (TR and WR series). The flaw is caused by insufficient sanitization of user-supplied input passed to system-level commands during the upgrade check process. An unauthenticated remote attacker can exploit this by sending a specially crafted request to the vulnerable interface. Successful exploitation allows the attacker to execute arbitrary shell commands with root privileges, leading to full system compromise. The vulnerability affects various firmware versions including TR1200 v2.4.15 and WR3000 v2.4.19.

Affected products

  • Cudy TR1200 v2.4.15
  • Cudy TR3000 v2.4.21
  • Cudy WR300 v2.4.25
  • Cudy WR1200 v2.4.23
  • Cudy WR1300 v2.4.22
  • Cudy WR1500 v2.3.10
  • Cudy WR3000 v2.4.19
  • Cudy WR3600 v2.3.16
  • Cudy WR6500 v2.3.15

Timeline

  • 2026-07-31: disclosed
  • 2026-07-31: advisory

References

Related threats