PT-2026-64186 · 9Router · 9Router
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
9router versions prior to 0.4.60
Description
An issue exists involving a chain of security flaws. A hardcoded default password allows authentication on fresh installations. Additionally, the LOCAL ONLY network gate can be bypassed using a spoofed Host header. Furthermore, unvalidated arguments are passed to the
child process.spawn() function during the registration of MCP plugins. A remote, unauthenticated attacker can exploit these flaws by logging in with the default credential and spoofing the Host header to access local-only routes, subsequently registering a malicious MCP plugin to achieve arbitrary code execution on the host operating system when the plugin's SSE endpoint is triggered.Recommendations
Update to version 0.4.60.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
9Router