Cudy WR3000 2.0 running firmware before 2.5.24 contains a...
Critical severity
Unreviewed
Published
Aug 19, 2026
to the GitHub Advisory Database
•
Updated Aug 19, 2026
Description
Published by the National Vulnerability Database
Aug 19, 2026
Published to the GitHub Advisory Database
Aug 19, 2026
Last updated
Aug 19, 2026
Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extracted secret to craft arbitrary JWT tokens and authenticate to the MQTT broker without legitimate credentials, gaining unauthorized access to the device's mesh networking interface.
References