Skip to finding
important · Firmware — Cudy routers

A fleet-wide Cudy mesh credential now has a demonstrated path to root on WR3000 and implicated P5 routers.

Affects

Cudy WR3000 2.0 Wi-Fi routers and P5 5G routers running the affected OpenWrt-derived firmware.

A forged JWT reaches the plaintext MQTT broker, and the consuming command handler passes attacker input to a root shell.

Detail and 4 sources

We do not know whether a network-only peer can derive the required device identifier or which P5 versions are affected.

Chain to watch
Reach TCP/1883 and obtain the target identifier→↓Forge a JWT with the fleet-wide secret→↓Publish a command consumed by the root shell→↓The cheapest path to the target identifier and the P5 version boundary remain unknown.
Unverified chainPublish the working exploit, derive the identifier from a stock device over the network, or compare affected and fixed P5 firmware.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 5, 2026