CVE-2026-71961PoC

MEDIUMCVSS 8.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT command interface. The sync_command binary forwards unsanitized input directly to a shell execution sink in command.lua, enabling attackers with access to the MQTT broker to exploit the default-enabled command execution path to achieve full root-level system compromise.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-08-20); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-20: 1Mentions · 2026-08-26: 1PoC Mentioned / Linked · 2026-08-20: 1PoC Mentioned / Linked · 2026-08-26: 1Exploit Tool / Code · 2026-08-20: 1Exploit Tool / Code · 2026-08-26: 1Patch / Workaround · 2026-08-20: 1Technical Details · 2026-08-20: 1Technical Details · 2026-08-26: 108-2008-26
Signal classification2 categories
PoC
150.0%
Exploit
150.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-08-201
PoC1
2026-08-261
Exploit1
Full discourse2 posts
  • Uriel Kosayev@UrielKosayev
    Exploit

    🚨 Two CVEs. One router. One complete chain to ROOT. Last week, we disclosed two vulnerabilities affecting the Cudy WR3000 2.0: 🔴 CVE-2026-71960 - Authentication Bypass CVSS v4.0: 9.3 Critical 🟠 CVE-2026-71961 - OS Command Injection CVSS v4.0: 8.7 High Individually, they are serious. Chained together, the story changes completely. 1/ During our firmware research, we recovered signing material that could be used to forge a valid JWT. That means bypassing the authentication boundary, accessing the MQTT interface, and reaching a vulnerable command path. The end result? Operating system command execution as root. 2/ This is exactly why I keep saying: Stop looking at vulnerabilities only as isolated CVEs. Attackers don't think in CVSS tables. They look for chains. One weakness opens the door. Another one gives you the keys. And suddenly, something that looked "limited" becomes a complete compromise. 3/ Then things became even more interesting. Shortly after our disclosure, Hunt & Benito independently released public exploit tooling reproducing the attack chain. Important clarification: We did NOT create, commission, or contribute to that exploit. But once public tooling exists, the barrier to reproducing the attack drops dramatically. And the research entered a second wave of international coverage. 4/ Our findings were covered by: SecurityBrief - original disclosure https://lnkd.in/de6YFUF7 SecurityBrief - public exploit follow-up https://lnkd.in/d6hx8c-h HackRead https://lnkd.in/eUBGwjzZ SecNews https://lnkd.in/d3xpfPiv BugsToday https://lnkd.in/dbend8WA 5/ For me, the most important takeaway isn't the headlines. It's the technical lesson: Security boundaries rarely fail in isolation. Authentication bypass alone tells one story. Command injection alone tells another. But connect them together and you get: Firmware -> signing material -> forged JWT -> MQTT access -> command injection -> ROOT That is the attack path that actually matters. 6/ This is the kind of research we want to push at Cipher Security Labs: Deep vulnerability research Full attack-chain analysis Understanding how weaknesses interact Product security Coordinated vulnerability disclosure Not just: "Here is a CVE." But: "Here is what an attacker can actually do with it." More research coming. Our CVE Tracker: https://ciphersecuritylabs.com/CVE-Tracker #CyberSecurity #VulnerabilityResearch #CVE #IoTSecurity #ProductSecurity #FirmwareSecurity #SecurityResearch #InfoSec

    Post summary

    The post details two critical vulnerabilities in a Cudy WR3000 router that, when chained, provide root access; it highlights publicly available exploit tooling that demonstrates the full attack path.

    12032594
    5.8K followersView on X
  • Hunt-Benito@HB_CyberSec
    PoC

    CVE-2026-71960 (CVSS 9.1): every Cudy WR3000 signs its mesh MQTT JWTs with one fleet-wide key — the DES literal guarding it ships in the public firmware. Forge a token, CONNECT :1883, chain CVE-2026-71961 → root. Fixed silently in 2.5.24. #Cudy #MQTT https://www.hunt-benito.com/blog/the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudys-wr3000-mesh-mqtt-broker/ https://t.co/9eXTtnckWm

    Post summary

    The post announces CVE‑2026‑71960 exposes a hard‑coded MQTT JWT secret, demonstrates how to forge a token to gain root via CVE‑2026‑71961, and notes a silent patch in firmware version 2.5.24.

    0000031
    3 followersView on X

Explore more