Brand profile · models not graded yet

Is Cudy Safe?

Cudy is a private router brand from Shenzhen, China, founded in 2018. FCC status, recent CVEs and how it handles security updates, explained.

Last reviewed: October 2026 · ismyroutersafe.com

Ownership & FCC Status
Owner
Shenzhen Cudy Technology Co., Ltd. (Shenzhen, China, private)
FCC Status
Existing models authorized; new models need a Conditional Approval (none held)
Ban Status
Not banned. Not named on the FCC Covered List
Manufacturing
Not confirmed (designed in China)
Models graded
Not yet

Security Verdict

Cudy is a privately held router brand based in Shenzhen, China, founded in 2018 and sold at retail and online. Its flaws since 2023 include a critical 2026 chain in the WR3000 that could give an attacker root access, which Cudy patched before public disclosure. None of its vulnerabilities are on CISA's exploited list. It has no public security advisory page, and under the 2026 FCC rule new Cudy models need a Conditional Approval, which Cudy does not hold.

Bottom line: Cudy fixed its most serious recent flaw quickly, but it publishes no security advisories, so it is hard to know when your model needs an update. Check for firmware updates regularly.

Rio Router
From the team behind this checker
Weighing up Cudy? See the router that scores an A on this same method.
  • SecureRooms. Smart devices live apart from your computers.
  • You approve every new device before it joins.
  • Rio VPN built in. First year included.
  • Set up in about 10 minutes from the app.
See Rio Router →
$199.99 · 1 year of VPN included, then $7.99/mo · 30-day returns · 1-year warranty. Rio builds this site, and its router is graded by the same method as every other.

Corporate Ownership Structure

Shenzhen Cudy Technology Co., Ltd. was founded in 2018 and is headquartered in Nanshan, Shenzhen, China. No stock listing was found and its owners are not disclosed. It describes itself as handling product R&D, manufacturing, sales and marketing, but does not state where its factories are.

Key Risk Factors

Critical flaw chain in a popular router
CVE-2026-71960 (CVSS 9.1, a hard-coded secret) and CVE-2026-71961 (CVSS 8.8) in the WR3000 v2.0 can be chained for root access. A public exploit was released in August 2026. The fix, firmware 2.5.24, shipped July 30, 2026.
No public security advisory page
No security advisory page or product security team was found. Cudy's contact page lists only a support email. Update cadence, end-of-life policy and automatic updates are not publicly confirmed.
Chinese company, ownership not disclosed
Cudy is a private company in Shenzhen, China. Its owners are not publicly disclosed, and state links were neither found nor ruled out.
No flaws on CISA's exploited list
No Cudy vulnerability is in the CISA Known Exploited Vulnerabilities catalog as of October 2026, and no botnet or state-actor reports were found.
Official OpenWrt firmware
Cudy offers official OpenWrt firmware images for many models, an open-source alternative to its stock firmware.

Known CVEs - Cudy Routers

The following vulnerabilities from the NIST National Vulnerability Database affect Cudy router models. This is a representative sample; the full CVE list may be longer.

CVE-2026-71960 Critical (CVSS 9.1)
Hard-coded secret in the WR3000 v2.0 mesh login before firmware 2.5.24.
CVE-2026-71961 High (CVSS 8.8)
OS command injection in WR3000 v2.0 mesh messaging that chains with CVE-2026-71960 for root access.
CVE-2026-32833 High (CVSS 8.8)
Authenticated OS command injection in the LT300 3.0 before firmware 2.5.12.
CVE-2026-4537 Medium (CVSS 4.7)
Command injection in the TR1200 IPsec settings.

Frequently Asked Questions

Cudy has no vulnerabilities on CISA's exploited list, and it fixed a critical 2026 flaw chain in the WR3000 before it was made public. However, it has no public security advisory page, its owners are not disclosed, and its update and end-of-life policies are not published. Check for firmware updates regularly.

Yes. Shenzhen Cudy Technology Co., Ltd. is a private company based in Shenzhen, China, founded in 2018. Its owners are not publicly disclosed, and where its routers are manufactured is not publicly confirmed.

No. Cudy is not named on the FCC Covered List. Under the March 2026 rule, routers designed or developed abroad count as foreign-produced, so new Cudy models need an FCC Conditional Approval, which Cudy does not hold. Previously authorized Cudy models can still be sold and used.

Cudy released firmware 2.5.24 for the WR3000 on July 30, 2026, fixing a critical flaw chain before it was disclosed. It does not publish security advisories, and its update cadence and end-of-life policy are not publicly confirmed. Many models can also run official OpenWrt firmware from Cudy.

Sources

Facts on this page come from these sources (publish date, or the date we checked the page).

CHECK YOUR SPECIFIC MODEL

Get your router's full security report

Check any specific model for CVEs, FCC status, security capabilities, and your personalized action plan.

Check a Router → Top 10 Safe Routers
Most home routers have hidden risks. Rio Router is the only one we rate A. See why →