CVE-2026-71960Disclosure

MEDIUMCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extracted secret to craft arbitrary JWT tokens and authenticate to the MQTT broker without legitimate credentials, gaining unauthorized access to the device's mesh networking interface.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-08-20); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-20: 1Mentions · 2026-08-25: 1Mentions · 2026-08-26: 1PoC Mentioned / Linked · 2026-08-20: 1PoC Mentioned / Linked · 2026-08-25: 1PoC Mentioned / Linked · 2026-08-26: 1Exploit Tool / Code · 2026-08-20: 1Exploit Tool / Code · 2026-08-26: 1Patch / Workaround · 2026-08-20: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-20: 1Technical Details · 2026-08-25: 1Technical Details · 2026-08-26: 108-2008-2508-26
Signal classification2 categories
Disclosure
266.7%
Exploit
133.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-08-201
Disclosure1
2026-08-251
Exploit1
2026-08-261
Disclosure1
Full discourse3 posts
  • Uriel Kosayev@UrielKosayev
    Disclosure

    🚨 Two CVEs. One router. One complete chain to ROOT. Last week, we disclosed two vulnerabilities affecting the Cudy WR3000 2.0: 🔴 CVE-2026-71960 - Authentication Bypass CVSS v4.0: 9.3 Critical 🟠 CVE-2026-71961 - OS Command Injection CVSS v4.0: 8.7 High Individually, they are serious. Chained together, the story changes completely. 1/ During our firmware research, we recovered signing material that could be used to forge a valid JWT. That means bypassing the authentication boundary, accessing the MQTT interface, and reaching a vulnerable command path. The end result? Operating system command execution as root. 2/ This is exactly why I keep saying: Stop looking at vulnerabilities only as isolated CVEs. Attackers don't think in CVSS tables. They look for chains. One weakness opens the door. Another one gives you the keys. And suddenly, something that looked "limited" becomes a complete compromise. 3/ Then things became even more interesting. Shortly after our disclosure, Hunt & Benito independently released public exploit tooling reproducing the attack chain. Important clarification: We did NOT create, commission, or contribute to that exploit. But once public tooling exists, the barrier to reproducing the attack drops dramatically. And the research entered a second wave of international coverage. 4/ Our findings were covered by: SecurityBrief - original disclosure https://lnkd.in/de6YFUF7 SecurityBrief - public exploit follow-up https://lnkd.in/d6hx8c-h HackRead https://lnkd.in/eUBGwjzZ SecNews https://lnkd.in/d3xpfPiv BugsToday https://lnkd.in/dbend8WA 5/ For me, the most important takeaway isn't the headlines. It's the technical lesson: Security boundaries rarely fail in isolation. Authentication bypass alone tells one story. Command injection alone tells another. But connect them together and you get: Firmware -> signing material -> forged JWT -> MQTT access -> command injection -> ROOT That is the attack path that actually matters. 6/ This is the kind of research we want to push at Cipher Security Labs: Deep vulnerability research Full attack-chain analysis Understanding how weaknesses interact Product security Coordinated vulnerability disclosure Not just: "Here is a CVE." But: "Here is what an attacker can actually do with it." More research coming. Our CVE Tracker: https://ciphersecuritylabs.com/CVE-Tracker #CyberSecurity #VulnerabilityResearch #CVE #IoTSecurity #ProductSecurity #FirmwareSecurity #SecurityResearch #InfoSec

    Post summary

    Cipher Security Labs disclosed two CVEs in a Cudy WR3000 router—a critical authentication bypass and a high‑severity command injection—that can be chained via forged JWTs to achieve root; third parties released a public exploit tool, but no evidence of active wild exploitation is reported.

    12032594
    5.8K followersView on X
  • Techsico IT@Techsico_IT
    Exploit

    Network admins: public exploit code chains Cudy WR3000 flaws CVE-2026-71960/71961 to root command execution. Patch to 2.5.24, block management/MQTT exposure, and segment routers from systems. Full Disclosure https://t.co/OJFD5ILgNJ

    Post summary

    Public exploit code chains for CVE‑2026‑71960/71961 allow root command execution on Cudy WR3000 routers; administrators should apply patch 2.5.24, block MQTT, and segment the routers.

    0000042
    8 followersView on X
  • Hunt-Benito@HB_CyberSec
    Disclosure

    CVE-2026-71960 (CVSS 9.1): every Cudy WR3000 signs its mesh MQTT JWTs with one fleet-wide key — the DES literal guarding it ships in the public firmware. Forge a token, CONNECT :1883, chain CVE-2026-71961 → root. Fixed silently in 2.5.24. #Cudy #MQTT https://www.hunt-benito.com/blog/the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudys-wr3000-mesh-mqtt-broker/ https://t.co/9eXTtnckWm

    Post summary

    The post announces CVE-2026-71960, detailing a hard‑coded MQTT JWT secret that allows token forging and a chain to root, and notes it was patched in firmware 2.5.24.

    0000031
    3 followersView on X

Explore more