The Cudy WR3000 mesh router gets rooted through a hard-coded JWT secret
Two flaws published on August 19, 2026, CVE-2026-71960 and CVE-2026-71961, let an accountless attacker forge an MQTT token and then run root commands on the Cudy WR3000 mesh router. Update to firmware 2.5.24 and take the mesh interface off your internet exposure.