{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/9router-0.4.59/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-63732"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["9router 0.4.59"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","remote-code-execution","hardcoded-credentials","webserver","nodejs"],"_cs_type":"advisory","_cs_vendors":["9router"],"content_html":"\u003cp\u003eA critical vulnerability chain, identified as CVE-2026-63732, affects 9router version 0.4.59. This chain enables a remote, unauthenticated attacker to gain arbitrary code execution on the underlying host operating system. The attack begins with exploitation of a hardcoded default password, '123456', which provides initial authentication to any fresh installation of the software. Following authentication, the attacker can bypass a network gate designed to restrict access to 'LOCAL_ONLY' routes by spoofing the Host header in HTTP requests. The final stage involves registering a malicious MCP plugin, leveraging unvalidated arguments passed to \u003ccode\u003echild_process.spawn()\u003c/code\u003e. This allows the attacker to embed and execute arbitrary commands, such as \u003ccode\u003enode -e \u0026lt;payload\u0026gt;\u003c/code\u003e, on the server when the plugin's Server-Sent Events (SSE) endpoint is subsequently triggered. This vulnerability chain poses a severe risk to organizations using affected 9router instances, as it permits full system compromise without prior authentication.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eA remote, unauthenticated attacker identifies a vulnerable 9router instance (version 0.4.59) exposed to the internet.\u003c/li\u003e\n\u003cli\u003eThe attacker gains initial access to the 9router web interface by authenticating with the hardcoded default password, \u0026quot;123456\u0026quot;.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts an HTTP request to a route intended for local access only, spoofing the Host header to bypass the \u003ccode\u003eLOCAL_ONLY\u003c/code\u003e network gate.\u003c/li\u003e\n\u003cli\u003eUtilizing the authenticated session and bypass, the attacker proceeds to register a malicious MCP plugin.\u003c/li\u003e\n\u003cli\u003eDuring plugin registration, the attacker injects unvalidated arguments into the application's call to \u003ccode\u003echild_process.spawn()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe injected arguments include a command payload, such as \u003ccode\u003enode -e \u0026lt;arbitrary_command\u0026gt;\u003c/code\u003e, intended for execution on the host operating system.\u003c/li\u003e\n\u003cli\u003eThe attacker triggers the newly registered plugin's Server-Sent Events (SSE) endpoint, causing the 9router application to execute the malicious command.\u003c/li\u003e\n\u003cli\u003eSuccessful execution of the injected command leads to arbitrary code execution (RCE) on the host operating system where 9router is running.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-63732 results in complete compromise of the underlying operating system hosting the 9router application. A remote, unauthenticated attacker can execute arbitrary commands, leading to full system control, data exfiltration, deployment of additional malware (e.g., ransomware, backdoors), or disruption of services. Given the critical severity (CVSS 9.9), the impact on affected organizations could be catastrophic, potentially leading to significant financial losses, reputational damage, and operational downtime. The NVD does not specify observed victim count or targeted sectors, but any organization using 9router 0.4.59 is at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade all 9router instances to version 0.4.60 or later to patch CVE-2026-63732.\u003c/li\u003e\n\u003cli\u003eChange the default password \u0026quot;123456\u0026quot; on any 9router installations, especially on versions prior to 0.4.60.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules in this brief to your SIEM and tune for your environment to detect suspicious \u003ccode\u003enode\u003c/code\u003e command executions.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive logging for process creation events on servers running 9router, specifically for the \u003ccode\u003eproduct: windows\u003c/code\u003e and \u003ccode\u003eproduct: linux\u003c/code\u003e logsources, to activate the provided Sigma rules.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T22:21:35Z","date_published":"2026-07-23T22:21:35Z","id":"https://feed.craftedsignal.io/briefs/2026-07-9router-cve-2026-63732/","summary":"A critical vulnerability chain, CVE-2026-63732, in 9router version 0.4.59 allows a remote, unauthenticated attacker to achieve arbitrary code execution on the host operating system by leveraging a hardcoded default password for initial access, bypassing a local-only network restriction via Host header spoofing, and exploiting unvalidated arguments during MCP plugin registration to execute malicious code when a plugin's SSE endpoint is triggered.","title":"9router Critical Vulnerability Chain Allows Remote Code Execution via Default Password and Plugin Exploitation","url":"https://feed.craftedsignal.io/briefs/2026-07-9router-cve-2026-63732/"}],"language":"en","title":"CraftedSignal Threat Feed - 9router 0.4.59","version":"https://jsonfeed.org/version/1.1"}