18 Total CVEs
18 AI Analyzed
0 CISA KEV
7 Critical

Profile

0% ended up actively exploited 0 of 18 added to CISA KEV
39% rated critical (CVSS 9.0+) 7 critical, 11 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

18 CVEs in the last 12 months

Products

  • 9router14
  • 9Router4

2 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-18 of 18 CVEs
CVE-2026-72860
Analyzed
8.5
decolua 9router

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destin...

2026-08-22
CVE-2026-63732
Analyzed
9.9
decolua 9router

9router allows remote code execution via a chain of vulnerabilities involving default credentials, host header spoofing, and insecure command executio...

2026-07-24
CVE-2026-63313
Analyzed
7.7
decolua 9router

9Router before 0

2026-07-24
CVE-2026-62328
Analyzed
7.5
decolua 9Router

9Router through version 0

2026-07-14
CVE-2026-62327
Analyzed
9.1
decolua 9Router

The decolua 9Router /api/usage/stats endpoint lacks authentication, allowing unauthenticated attackers to retrieve plaintext API keys for connected AI...

2026-07-14
CVE-2026-62312
Analyzed
8.8
decolua 9router

9Router is an AI router & token saver

2026-07-16
CVE-2026-59801
Analyzed
9.8
decolua 9Router

A missing authentication vulnerability in decolua 9Router allows unauthenticated remote attackers to interact with management API endpoints.

2026-07-14
CVE-2026-59800
Analyzed
9.8
decolua 9router

9Router contains an OS command injection vulnerability in an unauthenticated API endpoint, allowing remote attackers to execute arbitrary system comma...

2026-07-08
CVE-2026-56679
Analyzed
8.7
decolua 9router

9Router is an AI router & token saver

2026-07-16
CVE-2026-56677
Analyzed
8.6
decolua 9router

9Router is an AI router & token saver

2026-08-18
CVE-2026-56676
Analyzed
7.4
decolua 9router

9Router is an AI router & token saver

2026-07-12
CVE-2026-56675
Analyzed
8.3
decolua 9router

9Router is an AI router & token saver

2026-07-11
CVE-2026-55641
Analyzed
8.2
decolua 9Router

9Router is an AI router & token saver

2026-07-11
CVE-2026-55638
Analyzed
8.6
decolua 9router

9Router is an AI router & token saver

2026-07-11
CVE-2026-55501
Analyzed
7.3
decolua 9router

9Router is an AI router & token saver

2026-07-12
CVE-2026-55500
Analyzed
9.9
decolua 9router

The 9Router /api/settings/database endpoint allows unauthorized database export and import due to insufficient authentication checks.

2026-07-11
CVE-2026-49352
Analyzed
9.8
decolua 9router

9Router contains a hardcoded fallback JWT secret in its authentication routing and middleware, allowing unauthenticated attackers to forge authenticat...

2026-07-16
CVE-2026-46339
Analyzed
10
decolua 9router

9Router contains an authentication bypass vulnerability allowing unauthenticated remote command execution via unprotected API endpoints.

2026-07-16