What is CVE-2026-38713?
A command injection vulnerability has been discovered in multiple Cudy TR and WR series router models via the 'ipsec_conn' interface. This flaw could allow attackers to remotely execute arbitrary commands on the affected devices. Users should immediately apply the security update from the vendor.
Azərbaycanca: Bu boşluq Cudy markasının bir sıra TR və WR seriyalı marşrutlaşdırıcı modellərində aşkarlanıb. 'ipsec_conn' interfeysindəki command injection zəifliyi uzaqdan hücum edənə cihazda əmr icra etmək imkanı verir. Dərhal istehsalçının təqdim edəcəyi təhlükəsizlik yeniləməsi tətbiq olunmalıdır.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which Cudy devices are affected by CVE-2026-38713?
This vulnerability affects the TR and WR series router models from Cudy.
How to mitigate the CVE-2026-38713 vulnerability?
Users should immediately apply the security update provided by the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.