Known Vulnerabilities for 9router by Decolua
Listed below are 10 of the newest known vulnerabilities associated with "9router" by "Decolua".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-63732 json | 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticate... | Not Provided | 2026-07-23 | 2026-07-27 |
| CVE-2026-63313 json | 9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint... | Not Provided | 2026-07-23 | 2026-07-24 |
| CVE-2026-62328 json | 9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers t... | Not Provided | 2026-07-13 | 2026-07-15 |
| CVE-2026-62327 json | 9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers ... | Not Provided | 2026-07-13 | 2026-07-14 |
| CVE-2026-62312 json | 9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitrary co... | Not Provided | 2026-07-15 | 2026-07-16 |
| CVE-2026-59801 json | 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with... | Not Provided | 2026-07-13 | 2026-07-14 |
| CVE-2026-59800 json | 9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-instal... | Not Provided | 2026-07-07 | 2026-07-07 |
| CVE-2026-56679 json | 9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body to per... | Not Provided | 2026-07-15 | 2026-07-16 |
| CVE-2026-56678 json | 9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key buil... | Not Provided | 2026-07-15 | 2026-07-16 |
| CVE-2026-56676 json | 9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetching, bu... | Not Provided | 2026-07-10 | 2026-07-13 |