CRITICALVulnerability

CVE-2026-71960

Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extracted secret to craft arbitrary JWT tokens and authenticate to the MQTT broker without legitimate credentials, gaining unauthorized access to the device's mesh networking interface.

Properties

severity
CRITICAL
score
9.1
epss_score
0.00544
cve_id
CVE-2026-71960
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
published_at
2026-08-19T15:18:01.943
last_modified
2026-08-31T20:17:09.510
epss_percentile
0.4363

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Use of Hard-coded Credentials

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-71960 — Ninja Signal Threat Intelligence | Ninja Signal