Security Advisory

Cudy-SA-26-7-JEZZY4: Command Injection

Publish Time
2026-07-29 10:05:00 UTC+8
Last Updated
2026-07-29 14:00:00 UTC+8
Severity Important
Status Resolved

Abstract

A vulnerability allows command execution on the underlying system

Affected Products

Product Severity Fixed Release Availability
AX3000 2.5G Wi-Fi 6 Mini VPN Router, TR3000 1.0 Important update the firmware to 2.5.21

Detail

An OS command injection vulnerability exists in the wan setting interface of web page affected router due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands.

Acknowledgement

Jincheng Wang(@winmt), Professor Le Yu from Nanjing University of Posts and Telecommunications and Professor Xiapu Luo from Hong Kong Polytechnic University

Reference

CVE-2026-38709

Revision

2026-07-29 First publishment