THREAT OPS › Threat News › Cudy WR3000: Hard-coded JWT Secret to Root Command Injection
Cudy WR3000: Hard-coded JWT Secret to Root Command Injection
<p>Posted by Nir Yehoshua on Aug 19</p>Hello Full Disclosure list,<br /> <br /> Cipher Security Labs has published details for two vulnerabilities<br /> affecting Cudy WR3000 hardware revision 2.0 running firmware before<br /> version 2.5.24.<br /> <br /> CVE-2026-71960 - Hard-coded JWT Secret Authentication Bypass<br /> Severity: Critical, CVSS 9.3<br /> <br /> The device firmware contains a hard
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-71960cve
Original source: https://seclists.org/fulldisclosure/2026/Aug/68