CVE-2026-38709
Cudy Routers Command Injection Vulnerability
Halo Surface Signal: 5 out of 5 — more likely to be public-facing.
A command injection vulnerability exists in the `net.set_wan` interface of certain networking devices. Reachable via the internet, this flaw could permit unauthenticated attackers to execute arbitrary commands with root privileges on affected devices, potentially leading to a complete compromise. Confirming the presenc