Weakness in 9Router AI Router Backend Client-Side Header Handling
CVE-2026-56682

5.3MEDIUM

Key Information:

Vendor

Decolua

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-56682?

The 9Router AI Router is susceptible to an insufficient rate limiting vulnerability that can be exploited by remote unauthenticated attackers. Attackers can exploit this weakness by manipulating the client-supplied X-9r-Real-Ip header, enabling them to bypass progressive lockout mechanisms intended to prevent excessive failed login attempts. This flaw allows attackers to execute unthrottled password guessing attacks against the dashboard login endpoint, potentially leading to unauthorized access to administrative sessions if login credentials are compromised. The issue is rectified in version 0.5.6 of the product.

Affected Version(s)

9router < 0.5.6

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.