Weakness in 9Router AI Router Backend Client-Side Header Handling
CVE-2026-56682
5.3MEDIUM
What is CVE-2026-56682?
The 9Router AI Router is susceptible to an insufficient rate limiting vulnerability that can be exploited by remote unauthenticated attackers. Attackers can exploit this weakness by manipulating the client-supplied X-9r-Real-Ip header, enabling them to bypass progressive lockout mechanisms intended to prevent excessive failed login attempts. This flaw allows attackers to execute unthrottled password guessing attacks against the dashboard login endpoint, potentially leading to unauthorized access to administrative sessions if login credentials are compromised. The issue is rectified in version 0.5.6 of the product.
Affected Version(s)
9router < 0.5.6
