PT-2026-31584 · Unknown · Decolua 9Router

Cyberthoth

·

Published

2026-04-09

·

Updated

2026-04-10

·

CVE-2026-5842

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions decolua 9router versions up to 0.3.47
Description A security issue exists in decolua 9router that allows an attacker to bypass authorization. The vulnerability is located in an unknown function within the /api of the Administrative API Endpoint component. This can be exploited remotely. The exploit has been publicly disclosed.
Recommendations Upgrade to version 0.3.75 to resolve this issue.

Exploit

Fix

IDOR

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-5842
GHSA-XRRH-P7F2-27VM

Affected Products

Decolua 9Router