Home

Description

A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.3.75 is sufficient to resolve this issue. It is suggested to upgrade the affected component.

PUBLISHED Reserved 2026-04-08 | Published 2026-04-09 | Updated 2026-04-13 | Assigner VulDB




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
HIGH: 7.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
HIGH: 7.3CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
7.5AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C

Problem types

Authorization Bypass

Improper Authorization

Product status

0.3.0
affected

0.3.1
affected

0.3.2
affected

0.3.3
affected

0.3.4
affected

0.3.5
affected

0.3.6
affected

0.3.7
affected

0.3.8
affected

0.3.9
affected

0.3.10
affected

0.3.11
affected

0.3.12
affected

0.3.13
affected

0.3.14
affected

0.3.15
affected

0.3.16
affected

0.3.17
affected

0.3.18
affected

0.3.19
affected

0.3.20
affected

0.3.21
affected

0.3.22
affected

0.3.23
affected

0.3.24
affected

0.3.25
affected

0.3.26
affected

0.3.27
affected

0.3.28
affected

0.3.29
affected

0.3.30
affected

0.3.31
affected

0.3.32
affected

0.3.33
affected

0.3.34
affected

0.3.35
affected

0.3.36
affected

0.3.37
affected

0.3.38
affected

0.3.39
affected

0.3.40
affected

0.3.41
affected

0.3.42
affected

0.3.43
affected

0.3.44
affected

0.3.45
affected

0.3.46
affected

0.3.47
affected

0.3.75
unaffected

Timeline

2026-04-08:Advisory disclosed
2026-04-08:VulDB entry created
2026-04-08:VulDB entry last update

Credits

cyberthoth (VulDB User) reporter

References

vuldb.com/vuln/356298 (VDB-356298 | decolua 9router Administrative API Endpoint api authorization) vdb-entry

vuldb.com/vuln/356298/cti (VDB-356298 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/submit/790003 (Submit #790003 | 9Router Router 0.3.47-0.3.32 Authorization Bypass) third-party-advisory

github.com/decolua/9router/issues/431 issue-tracking

github.com/decolua/9router/issues/431 issue-tracking

github.com/deepcat1337/Free_Api_Exploit/tree/main exploit

github.com/decolua/9router/releases/tag/v0.3.75 patch

github.com/decolua/9router/ product

cve.org (CVE-2026-5842)

nvd.nist.gov (CVE-2026-5842)

Download JSON