PatchSiren

Shenzhen Cudy Technology Co., Ltd. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Shenzhen Cudy Technology Co., Ltd. CVE published 2026-08-19

CVE-2026-71961

The Cudy WR3000 2.0 device running firmware before 2.5.24 is vulnerable to an OS command injection attack. Authenticated attackers can execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT command interface. This vulnerability exists in the sync_command binary, which forwards unsanitized input directly to a shell execution sink in command.lua. As a result, a [truncated]

CRITICAL Shenzhen Cudy Technology Co., Ltd. CVE published 2026-08-19

CVE-2026-71960

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T15:18:01.943Z and has not been modified since then. The NVD entry is currently Received. CVE-2026-71960 is a critical vulnerability in Cudy WR3000 2.0 firmware before 2.5.24, allowing unauthenticated attackers to forge valid JWT tokens and gain unauthorized access to the device's mesh networking [truncated]

HIGH Shenzhen Cudy Technology Co., Ltd. CVE published 2026-06-26

CVE-2026-32833

CVE-2026-32833 is an OS command injection vulnerability in Cudy LT300 3.0 devices running firmware prior to version 2.5.12. The vulnerability allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the cbid.system.ntp.current POST parameter in the system time configuration interface. This can be exploited through the NTP settings endpoint, potentially leading to [truncated]