Research archive
2026Co-research · with Ductinn
AuthenticationCommand injectionOpen source

Unauthenticated RCE in 9Router

Missing authentication exposed privileged functionality; operating-system command injection turned that access into remote code execution.

The finding

9Router exposed sensitive application functions without an effective authentication boundary. One reachable path also passed attacker-controlled input into an operating-system command, creating a critical unauthenticated remote-code-execution chain.

The outcome

The maintainers published GHSA-g6g7-pvmx-m74p and credit vcth4nh and Ductinn as co-reporters. The advisory documents affected and patched versions for users operating the project.

This entry follows the primary GitHub advisory identifier because the advisory did not list a CVE at the time this profile was prepared.