What is CVE-2026-63732?
9router 0.4.59 contains a vulnerability chain including a hardcoded default password (123456), bypass of LOCAL_ONLY restriction via spoofed Host header, and unvalidated arguments to child_process.spawn() during MCP plugin registration. These flaws can lead to unauthenticated remote code execution on fresh installations. Users should immediately upgrade to version 0.4.60.
Azərbaycanca: 9router 0.4.59 versiyasında sərt kodlanmış default parol (123456), spoofed Host header ilə LOCAL_ONLY məhdudiyyətinin bypass edilməsi və MCP plugin qeydiyyatında child_process.spawn()-a ötürülən arqumentlərin yoxlanılmaması kimi zəifliklər zənciri mövcuddur. Bu zəifliklər təzə qurulmuş cihazlarda autentifikasiyasız uzaqdan kod icrasına səbəb ola bilər. İstifadəçilər dərhal 0.4.60 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
Which version of 9router is affected by CVE-2026-63732?
The vulnerability exists in 9router version 0.4.59.
What is the potential impact of exploiting the vulnerability chain in CVE-2026-63732?
This vulnerability chain can lead to unauthenticated remote code execution on fresh installations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.