Executive brief
A security vulnerability has been identified in several Cudy router models, which are devices used to provide internet connectivity and secure networking for homes and small offices. An attacker can exploit this flaw to take full control of the router by executing unauthorized commands with the highest level of administrative privileges. This could lead to the interception of network traffic, theft of sensitive data, or a complete shutdown of internet services.
Technical details
A command injection vulnerability exists in the 'ipsec_conn' interface of multiple Cudy router models. The flaw stems from insufficient sanitization of user-supplied input passed to system-level commands within the IPsec configuration component. An attacker can exploit this by sending specially crafted input to the affected interface, leading to arbitrary command execution with root privileges. The vulnerability affects various firmware versions across the TR and WR product lines, including TR1200 v2.4.15 and WR3000 v2.4.19. Users are advised to check the manufacturer's security advisory for firmware updates.
Affected products
- Cudy TR1200 v2.4.15
- Cudy TR3000 v2.4.21
- Cudy WR300 v2.4.25
- Cudy WR1200 v2.4.23
- Cudy WR1300 v2.4.22
- Cudy WR1500 v2.3.10
- Cudy WR3000 v2.4.19
- Cudy WR3600 v2.3.16
- Cudy WR6500 v2.3.15
Timeline
- 2026-07-31: disclosed: CVE published to NVD