important · Firmware — Cudy routers
A fleet-wide Cudy mesh credential now has a demonstrated path to root on WR3000 and implicated P5 routers.
Affects
Cudy WR3000 2.0 Wi-Fi routers and P5 5G routers running the affected OpenWrt-derived firmware.
A forged JWT reaches the plaintext MQTT broker, and the consuming command handler passes attacker input to a root shell.
Detail and 4 sources
We do not know whether a network-only peer can derive the required device identifier or which P5 versions are affected.
Chain to watch
Reach TCP/1883 and obtain the target identifier→↓Forge a JWT with the fleet-wide secret→↓Publish a command consumed by the root shell→↓The cheapest path to the target identifier and the P5 version boundary remain unknown.
Unverified chainPublish the working exploit, derive the identifier from a stock device over the network, or compare affected and fixed P5 firmware.
Sources
ResearchNew exploits and detections for Citrix NetScaler, PaperCut, Sangoma Switchvox, CUPS, Cudy routers, and more. - Initial AccessResearchDownloads for WR3000 2.0
– CudyCode / PoCGitHub - Hunt-Benito/the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt · GitHubVendorCudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT | Advisories | VulnCheck