Cudy WR3000: Hard-coded JWT Se... Note

Cudy WR3000: Hard-coded JWT Secret to Root Command Injection

Posted by Nir Yehoshua on Aug 19Hello Full Disclosure list, Cipher Security Labs has published details for two vulnerabilities affecting Cudy WR3000 hardware revision 2.0 running firmware before version 2.5.24. CVE-2026-71960 - Hard-coded JWT Secret Authentication Bypass Severity: Critical, CVSS 9.3 The device firmware contains a hard-coded HMAC signing secret used by the Mosquitto MQTT JWT authentication plugin. Because the secret can be recovered from the firmware image,...