Impact
The vulnerability exists in the Mosquitto MQTT broker plugin of the Cudy WR3000 2.0 firmware prior to version 2.5.24. A hard‑coded JWT HMAC signing secret is embedded in the firmware, enabling an attacker who obtains the firmware image, or a device on the network, to extract the secret. With the secret, the attacker can forge valid JWT tokens, authenticate to the MQTT broker without legitimate credentials, and gain unauthorized control of the device’s mesh networking interface. This compromises device integrity and may further grant access to local network traffic.
Affected Systems
The victim is a Shenzhen Cudy Technology Co., Ltd. WR3000 2.0 router running firmware before 2.5.24. No other vendors or product variants are listed in the CNA data.
Risk and Exploitability
The CVSS score of 9.3 classifies this threat as critical, while the EPSS score of <1% indicates a very low—but non‑zero—probability of exploitation. The flaw is not yet listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to first obtain the firmware image, which could come from physical access or from vendor download sites, before extracting the secret. Once the secret is known, forging a JWT token is trivial, allowing the attacker to authenticate to the MQTT broker over the network and bypass authentication.
OpenCVE Enrichment