Impact
Cudy WR3000 2.0 firmware versions prior to 2.5.24 contain an OS command injection flaw (CWE-78) in the sync_command binary. Unsanitized input sent through the mesh MQTT command handler is forwarded directly to a shell execution sink in command.lua, which allows authenticated attackers with access to the MQTT broker to run arbitrary OS commands as root. The attacker can therefore achieve full system compromise, including data theft, disruption, and persistence.
Affected Systems
Shenzhen Cudy Technology Co., Ltd. wireless routers running WR3000 2.0 firmware before version 2.5.24 are affected.
Risk and Exploitability
The CVSS score is 8.7, indicating that the vulnerability has high severity. EPSS is 3%, indicating a moderate likelihood of exploitation, and it is not listed in the CISA KEV catalog. It requires the attacker to be authenticated to the MQTT broker, so an attacker with network access to the device’s MQTT service can exploit the default enabled command execution path to elevate privileges to root. The attack could be executed remotely over the local network or the internet if the MQTT broker is exposed.
OpenCVE Enrichment