Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

9router — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in 9router, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of security vulnerabilities associated with the 9router product line, focusing on software weakness types identified by security researchers and automated scanning tools. It collects a wide range of defect categories, including buffer overflows, injection flaws, cross-site scripting, and authentication bypasses, covering historical data from 2018 through the present day to capture both legacy issues and recent findings. Here, users can systematically track vendor advisories as they are released, gain a deeper understanding of specific weakness classes and their impact on router firmware, and examine the complete vulnerability history of this specific product to assess its long-term security posture. This resource serves as a centralized reference point for security professionals, system administrators, and developers who need to evaluate the risk profile of 9router devices before deployment or during maintenance cycles. By presenting raw vulnerability data without interpretation, the page allows stakeholders to perform their own risk analysis and prioritize patching efforts based on severity scores and exploit availability. The information is sourced from public databases, vendor announcements, and independent security research, ensuring a broad and accurate view of the threat landscape surrounding this network infrastructure component. This structured approach facilitates better decision-making regarding device upgrades, configuration hardening, and network segmentation strategies.

Vendor: decolua

CVE IDTitleCVSSSeverityPublished
CVE-2026-63313 9Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch CWE-918 7.7 High2026-07-23
CVE-2026-63732 9router before 0.4.60 Remote Code Execution via default password CWE-78 9.9 Critical2026-07-23
CVE-2026-62312 9Router: Authenticated RCE via Unvalidated MCP Plugin Arguments CWE-78 8.8 High2026-07-15
CVE-2026-56678 9Router: Kiro region injection allows authenticated SSRF with Authorization header forwarding CWE-20 6.4 Medium2026-07-15
CVE-2026-56679 9Router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade CWE-915--2026-07-15
CVE-2026-49353 9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING CWE-290 7.5 High2026-07-15
CVE-2026-49352 9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass CWE-798 9.8 Critical2026-07-15
CVE-2026-46339 9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes CWE-78 10.0 Critical2026-07-15
CVE-2026-62328 9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints CWE-862 7.5 High2026-07-13
CVE-2026-62327 9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats CWE-306 9.1 Critical2026-07-13
CVE-2026-59801 9Router 0.4.41 - Unauthenticated API Exposure via /api/providers CWE-306 9.8 Critical2026-07-13
CVE-2026-56675 9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs CWE-287 8.3 High2026-07-10
CVE-2026-55638 9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass CWE-862 8.6 High2026-07-10
CVE-2026-55641 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF CWE-290 8.2 High2026-07-10
CVE-2026-56676 9router: Image prefetch DNS rebinding allows SSRF to internal services CWE-367 7.4 High2026-07-10
CVE-2026-55500 9router: Exposure of Sensitive Information and Unprotected Database Import/Export Allows Complete Credential Theft and Database Takeover CWE-200 9.9 Critical2026-07-10
CVE-2026-55501 9router: Login brute-force protection bypass via spoofed X-Forwarded-For header CWE-307 7.3 High2026-07-10
CVE-2026-59800 9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint CWE-78 9.8 Critical2026-07-07
CVE-2026-10269 decolua 9router HTTP Header dashboardGuard.js isAuthenticated improper authorization CWE-285 6.3 Medium2026-06-01
CVE-2026-5842 decolua 9router Administrative API Endpoint api authorization CWE-639 7.3 High2026-04-09

All 20 known CVE vulnerabilities affecting 9router with full Chinese analysis, references, and POCs where available.