PT-2026-78446 · Mosquitto+1 · Mosquitto+1

·

CVE-2026-71960

·

Published

2026-08-19

·

Updated

2026-08-31

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cudy WR3000 2.0 versions prior to 2.5.24
Description The Mosquitto MQTT broker authentication plugin contains a hard-coded JWT HMAC signing secret. This allows unauthenticated attackers to extract the secret from the firmware image and forge valid JSON Web Tokens (JWT), which are compact, URL-safe means of representing claims to be transferred between two parties. By crafting arbitrary tokens, attackers can authenticate to the MQTT broker without legitimate credentials and gain unauthorized access to the device mesh networking interface.
Recommendations Update Cudy WR3000 2.0 to firmware version 2.5.24 or later.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71960

Affected Products

Mosquitto
Wr3000 2.0