CVE-2026-71961
Cudy WR3000 2.0 OS Command Injection via Mesh MQTT Command Handler
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT command interface. The sync_command binary forwards unsanitized input directly to a shell execution sink in command.lua, enabling attackers with access to the MQTT broker to exploit the default-enabled command execution path to achieve full root-level system compromise.
| CWE | CWE-78 |
| Vendor | shenzhen cudy technology co., ltd. |
| Product | wr3000 2.0 |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for shenzhen cudy technology co., ltd. wr3000 2.0
Be the first to know when new high vulnerabilities affecting shenzhen cudy technology co., ltd. wr3000 2.0 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Shenzhen Cudy Technology Co., Ltd. / WR3000 2.0
0 < 2.5.24
References
Credits
Nir Yehoshua