CVE-2026-63732 | decolua 9router up to 0.4.59 MCP Plugin Registration child_process.spawn default password

SecurityVulns

A vulnerability was found in decolua 9router up to 0.4.59. It has been declared as very critical. Affected by this vulnerability is the function child_process.spawn of the component MCP Plugin Registration. Executing a manipulation can lead to use of default password.

This vulnerability is tracked as CVE-2026-63732. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More