Two critical vulnerabilities in home and professional mesh routers (mesh network routers, where multiple devices work together to provide unified coverage of a space) Cudy WR3000 hardware revision 2.0, which now pose a direct threat to Greek owners, were discovered by the Israeli research company Cipher Security Labs. The biggest problem is that on August 20, 2026, an independent team of researchers named Hunt & Benito published a full PoC (Proof of Concept) on GitHub with ready-made exploit tools, drastically reducing the technical barrier to attack.

The combination of the two vulnerabilities — CVE-2026-71960 (Critical, CVSS 9.3) and CVE-2026-71961 (High, CVSS 8.7) — allows an attacker without an account on the router and without physical access to execute operating system commands with superuser (root) privileges. The Cudy WR3000 is sold by Greek retailers, although the specific hardware revision distinction is not always discernible on product pages.
See also: Europol: "Strike" in online fraud ring — Victims also in Greece
CVE-2026-71960: The built-in key that opens "every box"
The first vulnerability concerns a hard-coded HMAC (Hash-based Message Authentication Code) signing secret used by the JWT (JSON Web Token) authentication plugin of the Mosquitto MQTT broker (a central intermediary for the IoT device communication protocol) in the router firmware. Because the firmware image is publicly downloadable from Cudy's website, an attacker can analyze it and retrieve the cryptographic material that should be unique to each device.
As Cipher Security Labs researcher Nir Yehoshua in an exclusive interview with the SecNews editorial team: “The most important lesson is that an embedded signing secret is not a strong authentication threshold. When the same secret can be recovered from downloaded firmware, an attacker can replicate the trust that the broker was designed to grant only to legitimate customers.” The official CVSS v4 vector is AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N, i.e. a network attack without user interaction.
CVE-2026-71961: Operating system commands as root
The second vulnerability is located in the command path of the identified mesh MQTT interface. The sync_command forwards externally controlled command data to the router's command handler, while the command.lua reaches a shell execution point without proper isolation of special characters (shell metacharacters — symbols such as ;, |, && that the operating system interprets as commands).
Because the vulnerable path is executed with root privileges, an attacker who gains access to the MQTT broker with a valid token can execute arbitrary commands at the highest privilege level of the device. “The second vulnerability shows why vulnerability chains should be evaluated as systems, not as individually documented issues. An authenticated execution command may seem limited, until a separate vulnerability allows the attacker to construct the required authentication,” Yehoshua emphasizes.

PoC publication by Hunt & Benito changes the landscape
By August 20, 2026, the two vulnerabilities existed as technical publications through the GHSA and VulnCheck advisory. On that day, the independent research team Hunt & Benito published a complete exploit guide titled "The Same Key Opens Every Box" on GitHub, containing four working Python tools.
The tools include extract_firmware.py to decompress the firmware image, decrypt_bdinfo.py to retrieve the DES key 88T3j05dtFu8= that encrypts the secret in the device's memory, forge_jwt.py to forge a valid HS256 token, and finally mqtt_takeover.py to connect to the MQTT broker on port 1883 and optionally exploit the chain to execute operating system commands via io.popen. Cipher Security Labs has clarified that it is not related to the published PoC, which comes exclusively from Hunt & Benito as independent research.
See also: Suspect arrested for global crypto fraud — Arrests also in Greece
What does it mean for Greek Cudy WR3000 owners?
The affected range is specific: Cudy WR3000 hardware revision 2.0 with firmware older than 2.5.24. The official update from Cudy was released on July 30, 2026 as version 2.5.24, removing the plaintext listener (the process that accepts incoming connections) on port 1883, completely removing the secret from the bdinfo area, and adding mandatory mutual TLS authentication. However, Cipher Security Labs has filed technical observations on individual elements of the new version, which Cudy responded that do not demonstrate full exploitation on a physical device.
Greek owners should immediately check two things: first, what hardware revision their device has (the indication is usually found on the back label of the router or on the management panel), and second, what firmware version it is running. If it is revision 2.0 with a version older than 2.5.24, an immediate upgrade is imperative. The editorial team of SecNews points out that, although no publicly active exploitation has been documented in Greece, the existence of a public PoC makes the reaction time extremely limited.

Who is Cipher Security Labs — The Leading Team Behind the Disclosure
Cipher Security Labs has established itself as one of the most specialized deep technical security research companies in the world, specializing in real software systems, embedded systems and adversarial techniques. The company's philosophy focuses on the full technical documentation of each vulnerability — from firmware reverse engineering to verification in controlled emulation environments — with a methodology recognized by leading security software vendors.
Behind the Cudy WR3000 vulnerability disclosure are two internationally recognized researchers. Nir Yehoshua, co-founder and Offensive Research Lead, has over a decade of experience in vulnerability research, reverse engineering, and malware analysis. He is a former Chief Researcher and CISO at an EDR (Endpoint Detection and Response) company, a former member of the Israeli military’s security research and incident response team, and the author of the book Antivirus Bypass Techniques. He is also inducted into the Halls of Fame by Bitdefender, McAfee, Intel, Bosch, eScan, and FACEIT — a collection of accolades that attest to the breadth and depth of his research.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Uriel Kosayev, Co-Founder and Malware Research Lead, is an internationally recognized cybersecurity researcher, reverse engineer, and keynote speaker at security conferences. He is the founder of TrainSec Academy, one of the most recognized training academies in advanced malware analysis techniques, and co-author of the books Antivirus Bypass Techniques and MAoS — Malware Analysis on Steroids. His expertise spans malware analysis, offensive security, incident response, deep malware research, and advanced adversary tactics. The Cudy WR3000 case is a prime example of their methodology: full firmware reverse engineering, structural cryptographic vulnerability detection, exploit chain documentation, and coordinated vendor disclosure.
Protection measures beyond firmware updates
In addition to the upgrade, the SecNews technical team recommends ensuring that MQTT and mesh management services are not accessible from untrusted networks, checking the router's firewall and port forwarding rules, separating the network infrastructure from user devices where possible (network segmentation), and monitoring for unexpected configuration changes. For business premises, reporting to the Cybercrime Prosecution (telephone 11188) is necessary in case of suspicious activity.
Evolution (21/08/2026): Performance of the exploitation chain at Hunt & Benito
In a briefing to the SecNews editorial team on August 21, 2026, researcher Nir Yehoshua of Cipher Security Labs clarified the sequence of events and called for an explicit separation of roles. The independent external team Hunt & Benito is the one that published the exploit chain, which practically connects CVE-2026-71960 to CVE-2026-71961: it extracts the necessary data from the firmware image, creates a JWT token that is accepted by the mesh MQTT broker and can reach the execution of a command as root. “The code was not created or published by Cipher Security Labs,” Yehoshua emphasized, asking for a clear attribution of the exploit chain to Hunt & Benito, while the initial technical research and disclosure of the two vulnerabilities remains the work of Cipher Security Labs.
The exact scope of the vulnerability remains unchanged: Cudy WR3000 hardware revision 2.0 with firmware older than 2.5.24. The updated version 2.5.24 removes the listener on port 1883 and the static secret, switching to mTLS (mutual TLS authentication, where both parties authenticate themselves with digital certificates). The researcher notes that network access to the MQTT service is still required and that there is, so far, no evidence of active exploitation in practice. However, the publication of the tools makes the chain significantly easier to reproduce — which raises the real level of risk for uninformed owners of this generation of hardware.
The Cudy WR3000 case highlights a structural problem in the IoT industry: the use of shared secrets across all units of a product line turns extracting a unique key from a firmware sample into a universal authentication bypass. The SecNews editorial team will follow the development of the case and will update with the upcoming interview with Nir Yehoshua of Cipher Security Labs after August 24, as well as with any new technical publications from Hunt & Benito regarding the exploit chain.
