THREATOPS
THREAT OPSThreat News › Cudy WR3000: Hard-coded JWT Secret to Root Command Injection

Cudy WR3000: Hard-coded JWT Secret to Root Command Injection

medfulldisclosurePublished 2026-08-20

<p>Posted by Nir Yehoshua on Aug 19</p>Hello Full Disclosure list,<br /> <br /> Cipher Security Labs has published details for two vulnerabilities<br /> affecting Cudy WR3000 hardware revision 2.0 running firmware before<br /> version 2.5.24.<br /> <br /> CVE-2026-71960 - Hard-coded JWT Secret Authentication Bypass<br /> Severity: Critical, CVSS 9.3<br /> <br /> The device firmware contains a hard

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://seclists.org/fulldisclosure/2026/Aug/68