<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 03:50:29 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-71960 — Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-71960</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Shenzhen Cudy Technology Co., Ltd. WR3000 2.0, Shenzhen Cudy Technology Co., Ltd. P5 V1.1&lt;/p&gt;
&lt;p&gt;Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker&amp;#39;s authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extracted secret to craft arbitrary JWT tokens and authenticate to the MQTT broker without legitimate credentials, gaining unauthorized access to the device&amp;#39;s mesh networking interface.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Shenzhen Cudy Technology Co., Ltd. WR3000 2.0, Shenzhen Cudy Technology Co., Ltd. P5 V1.1&lt;/p&gt;
&lt;p&gt;Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker&amp;#39;s authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extracted secret to craft arbitrary JWT tokens and authenticate to the MQTT broker without legitimate credentials, gaining unauthorized access to the device&amp;#39;s mesh networking interface.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-71960</guid>
    </item>
  </channel>
</rss>
