CVE-2026-38711

Cudy · Network Routers (TR1200, TR3000, WR300, WR1200, WR1300, WR1500, WR3000, WR3600, WR6500)

A command injection vulnerability in the system.upgrade_check interface allows unauthenticated attackers to execute arbitrary commands as root on multiple Cudy router models.

Executive summary

This critical command injection vulnerability in Cudy routers allows unauthenticated remote attackers to achieve full system compromise with root-level privileges.

Vulnerability

This is a command injection vulnerability residing in the system.upgrade_check interface. The flaw allows unauthenticated attackers to inject and execute arbitrary commands as the root user through crafted input.

Business impact

With a CVSS score of 9.8, this vulnerability represents a critical risk to business operations. Successful exploitation enables full administrative control over the affected network hardware, which could lead to unauthorized network access, data interception, or the permanent bricking of infrastructure devices.

Remediation

Immediate Action: Consult the vendor advisory at the provided URL to verify if a firmware update is available for your specific model and apply it immediately.

Proactive Monitoring: Review system logs for unusual activity originating from the upgrade_check interface and monitor network traffic for unexpected outbound connections from router management interfaces.

Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses only, and ensure that the management interface is not exposed to the public internet.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical severity of this flaw, administrators should prioritize the identification of exposed Cudy devices within their environment. If a patch is not yet available, immediately isolate affected devices from the internet until a secure firmware version can be deployed.