Threat Advisory

9router Vulnerabilities Enable Login Lockout and IP Forgery

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

9router is affected by two vulnerabilities caused by its reliance on the client-controlled X-9r-Real-Ip HTTP header. A remote unauthenticated attacker can spoof X-9r-Real-Ip: 127.0.0.1 to bypass API-key authentication for the public LLM API when the application is deployed without the trusted custom-server.js wrapper. This can enable unauthorized use of configured LLM provider resources and consumption of paid API credits. Attackers can also rotate spoofed X-9r-Real-Ip values to create separate rate-limit buckets and bypass the dashboard's login brute-force lockout enabling unlimited password-guessing attempts. Both vulnerabilities have been addressed by the vendor.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

9router is affected by two vulnerabilities caused by its reliance on the client-controlled X-9r-Real-Ip HTTP header. A remote unauthenticated attacker can spoof X-9r-Real-Ip: 127.0.0.1 to bypass API-key authentication for the public LLM API when the application is deployed without the trusted custom-server.js wrapper. This can enable unauthorized use of configured LLM provider resources and consumption of paid API credits. Attackers can also rotate spoofed X-9r-Real-Ip values to create separate rate-limit buckets and bypass the dashboard's login brute-force lockout enabling unlimited password-guessing attempts. Both vulnerabilities have been addressed by the vendor.[emaillocker id="1283"]

CVE-2026-56681 (CVSS 7.3 — High): An unauthenticated remote attacker can bypass API-key enforcement on the public LLM API by sending X-9r-Real-Ip: 127.0.0.1 in the HTTP request header, allowing them to access instance owner's configured provider resources.

CVE-2026-56682 (CVSS 5.3 — Medium): It is a vulnerability that allows remote unauthenticated attackers to bypass dashboard login lockouts by rotating spoofed X-9r-Real-Ip header values when custom-server.js does not derive the address from the TCP socket address.

 

RECOMMENDATIONS:

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-5mj8-gf6m-fhw8
https://github.com/advisories/GHSA-32gc-64m7-hj7v

[/emaillocker]
crossmenu