Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT command interface. The sync_command binary forwards unsanitized input directly to a shell execution sink in command.lua, enabling attackers with access to the MQTT broker to exploit the default-enabled command execution path to achieve full root-level system compromise.
History

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Shenzhen Cudy Technology
Shenzhen Cudy Technology wr3000 2.0
Vendors & Products Shenzhen Cudy Technology
Shenzhen Cudy Technology wr3000 2.0

Thu, 20 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT command interface. The sync_command binary forwards unsanitized input directly to a shell execution sink in command.lua, enabling attackers with access to the MQTT broker to exploit the default-enabled command execution path to achieve full root-level system compromise.
Title Cudy WR3000 2.0 OS Command Injection via Mesh MQTT Command Handler
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-08-19T14:28:45.994Z

Updated: 2026-08-20T15:54:01.317Z

Reserved: 2026-08-08T16:43:04.177Z

Link: CVE-2026-71961

cve-icon Vulnrichment

Updated: 2026-08-20T15:53:57.272Z

cve-icon NVD

Status : Received

Published: 2026-08-19T15:18:02.083

Modified: 2026-08-20T16:17:52.367

Link: CVE-2026-71961

cve-icon Redhat

No data.