Impact
A command injection flaw exists in the system.setclock interface of certain Cudy router models. An attacker can send a specially crafted request that tricks the device into executing arbitrary command strings as the root user. The vulnerability enables full system compromise, allowing the attacker to read, modify or delete any data, install malware, or use the device as a pivot point for further attacks.
Affected Systems
Cudy TR1200 firmware version 2.4.15 and Cudy TR3000 firmware version 2.4.21 are affected. No other vendors or products are known to be impacted.
Risk and Exploitability
The ability to execute commands as root makes this a high‑severity vulnerability, though the EPSS score is 3%, indicating low current exploitation momentum. The CVSS score is 7.2. The flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vectors involve remote access to the network interface that exposes the system.setclock API, potentially requiring authentication or privileged access to the device’s management interface.
OpenCVE Enrichment