9Router Unauthenticated OS Command Injection via Tailscale Install Endpoint
criticalAgentCode Execution9Router, a platform used to manage/orchestrate agent-related infrastructure, has a critical unauthenticated remote code execution flaw in its tunnel installation endpoint. An attacker can send a crafted 'sudoPassword' field that gets fed directly into a shell process, resulting in arbitrary OS command execution as root in many configurations. This is a classic infrastructure vulnerability with severe impact, already showing exploitation evidence in the wild.
Updated Jul 8, 2026 · CVSS 9.8