Security Advisory

Cudy-SA-26-7-GNHH9V: Command Injection

Publish Time
2026-07-24 10:05:00 UTC+8
Last Updated
2026-07-24 14:46:00 UTC+8
Severity Important
Status Resolved

Abstract

A vulnerability allows command execution on the underlying system

Affected Products

Product Severity Fixed Release Availability
Cudy Software Platform 2.5.x, CSP 2.5.x Important Upgrade firmware to v2.5.12 or higher version

Detail

An OS command injection vulnerability exists in the NTP service of the affected router due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. Exploitation requires specific conditions such as NTP being enabled and ability to influence ACS-delivered commands, compromise or control an ACS server.

Acknowledgement

wsparks

Reference

CWE-78: Improper Neutralization of Special Elements used in an OS Command

Revision

2026-07-24 First publishment