Sploitus

CVE-2026-71960

1 known exploit for CVE-2026-71960

Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extracted secret to craft arbitrary JWT tokens and authenticate to the MQTT broker without legitimate credentials, gaining unauthorized access to the device's mesh networking interface.

Affected products
Wr3000 2.0
CVSS 4.0
9.3 CRITICAL
CVSS 3.1
9.1 CRITICAL
EPSS
0.4% (34th percentile)
Weakness
CWE-798
NVD status
Received
Published
2026-08-19
CVE-2026-71960 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-71960

Proof-of-concept code and exploit modules indexed by Sploitus