Cudy manufactures a niche line of networking devices and firmware, with vulnerability exposure concentrated in its LT400 and LT500E router product families. The recurring weakness classes center on cross-site scripting in web interfaces and hard-coded credentials embedded in firmware, typical of embedded networking equipment with limited input validation and credential-management infrastructure.
The number and severity of CVEs published that impact products developed by Cudy over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9725HIGH A vulnerability was identified in Cudy LT500E up to 2.3.12. Affected is an unknown function of the file /squashfs-root/etc/shadow of the component Web Interface. The manipulation l | Aug 31, 2025 | 8.8 | 27 | NO | NO |
CVE-2023-31853MEDIUM Cudy LT400 1.13.4 is vulnerable Cross Site Scripting (XSS) in /cgi-bin/luci/admin/network/bandwidth via the icon parameter. | Jul 17, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-31851MEDIUM Cudy LT400 1.13.4 is has a cross-site scripting (XSS) vulnerability in /cgi-bin/luci/admin/network/wireless/status via the iface parameter. | Jul 17, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-31852MEDIUM Cudy LT400 1.13.4 is vulnerable to Cross Site Scripting (XSS) in cgi-bin/luci/admin/network/wireless/config via the iface parameter. | Jul 17, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cudy.
Media articles that mention a CVE ID that affects a product developed by Cudy — matched by CVE ID, not by vendor name.