PT-2026-64186 · 9Router · 9Router

·

CVE-2026-63732

·

Published

2026-07-23

·

Updated

2026-07-28

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 9router versions prior to 0.4.60
Description An issue exists involving a chain of security flaws. A hardcoded default password allows authentication on fresh installations. Additionally, the LOCAL ONLY network gate can be bypassed using a spoofed Host header. Furthermore, unvalidated arguments are passed to the child process.spawn() function during the registration of MCP plugins. A remote, unauthenticated attacker can exploit these flaws by logging in with the default credential and spoofing the Host header to access local-only routes, subsequently registering a malicious MCP plugin to achieve arbitrary code execution on the host operating system when the plugin's SSE endpoint is triggered.
Recommendations Update to version 0.4.60.

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63732

Affected Products

9Router