
🚨 Two CVEs. One router. One complete chain to ROOT. Last week, we disclosed two vulnerabilities affecting the Cudy WR3000 2.0: 🔴 CVE-2026-71960 - Authentication Bypass CVSS v4.0: 9.3 Critical 🟠 CVE-2026-71961 - OS Command Injection CVSS v4.0: 8.7 High Individually, they are serious. Chained together, the story changes completely. 1/ During our firmware research, we recovered signing material that could be used to forge a valid JWT. That means bypassing the authentication boundary, accessing the MQTT interface, and reaching a vulnerable command path. The end result? Operating system command execution as root. 2/ This is exactly why I keep saying: Stop looking at vulnerabilities only as isolated CVEs. Attackers don't think in CVSS tables. They look for chains. One weakness opens the door. Another one gives you the keys. And suddenly, something that looked "limited" becomes a complete compromise. 3/ Then things became even more interesting. Shortly after our disclosure, Hunt & Benito independently released public exploit tooling reproducing the attack chain. Important clarification: We did NOT create, commission, or contribute to that exploit. But once public tooling exists, the barrier to reproducing the attack drops dramatically. And the research entered a second wave of international coverage. 4/ Our findings were covered by: SecurityBrief - original disclosure https://lnkd.in/de6YFUF7 SecurityBrief - public exploit follow-up https://lnkd.in/d6hx8c-h HackRead https://lnkd.in/eUBGwjzZ SecNews https://lnkd.in/d3xpfPiv BugsToday https://lnkd.in/dbend8WA 5/ For me, the most important takeaway isn't the headlines. It's the technical lesson: Security boundaries rarely fail in isolation. Authentication bypass alone tells one story. Command injection alone tells another. But connect them together and you get: Firmware -> signing material -> forged JWT -> MQTT access -> command injection -> ROOT That is the attack path that actually matters. 6/ This is the kind of research we want to push at Cipher Security Labs: Deep vulnerability research Full attack-chain analysis Understanding how weaknesses interact Product security Coordinated vulnerability disclosure Not just: "Here is a CVE." But: "Here is what an attacker can actually do with it." More research coming. Our CVE Tracker: https://ciphersecuritylabs.com/CVE-Tracker #CyberSecurity #VulnerabilityResearch #CVE #IoTSecurity #ProductSecurity #FirmwareSecurity #SecurityResearch #InfoSec
Post summary
Cipher Security Labs disclosed two CVEs in a Cudy WR3000 router—a critical authentication bypass and a high‑severity command injection—that can be chained via forged JWTs to achieve root; third parties released a public exploit tool, but no evidence of active wild exploitation is reported.


