PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Network Vulnerabilities·Updated Sep 26, 2026

CVE-2026-56681 Scanner

CVE-2026-56681 Scanner - Insecure Authorization vulnerability in 9router

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
7.3
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper trust the client-supplied X-9r-Real-Ip header in src/dashboardGuard.js when isLocalRequest decides whether canAccessPublicLlmApi may skip API-key validation for /api/v1/* routes. A remote unauthenticated attacker can set X-9r-Real-Ip to 127.0.0.1 and be classified as a local client, including on the verified GET /api/v1/models route. This permits unauthorized use of the instance owner's configured LLM providers, consumption of paid credits, and enumeration of configured providers and models. This issue is fixed in version 0.5.6.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
9routerby decolua
< 0.5.6
Updated Sep 26, 2026View on NVD →
Detail

The 9router is commonly used in network environments to route traffic and manage API requests. It's popular among developers and network administrators for controlling access to local and remote API routes. The software is intended for environments that require efficient API request management and traffic routing. Its usage spans across small to medium-sized networks, offering tools to optimize network performance and resource usage. 9router has features for API consumption and resource management, making it integral to systems needing strict access controls.

The vulnerability in 9router involves insecure authorization, allowing attackers to bypass API-key validation. This flaw is present due to the router's reliance on client-supplied X-9r-Real-Ip header for authentication processes. When exploited, malicious actors gain unauthorized access without needing legitimate credentials. The vulnerability is significant due to its potential to allow unauthorized API interactions, consumed paid credits, and enumerate sensitive models.

The vulnerability details reveal that an attacker can manipulate the X-9r-Real-Ip header to bypass the system's authentication checks. With access to local API routes, unauthorized operations can be conducted, compromising service integrity. The flaw specifically affects endpoints relying on the header for access validation, exposing the system to potential misuse without a need for initial access tokens. Unchecked, this vulnerability can severely disrupt service operations.

When exploited, this vulnerability can lead to unauthorized API usage, escalating operational costs due to consumed resources. It opens the doorway to confidential data exposure through legitimate model enumeration processes. Additionally, it compromises the service's security posture, leading to potential financial and reputational damages. Organizations may face increased risks of system manipulation and unauthorized resource consumption.

REFERENCES

Solution Advice
  • Update 9router to version 0.5.6 or later.
  • Implement stricter validation checks for the X-9r-Real-Ip header input to prevent unauthorized access.
  • Regularly audit the access control mechanisms and API endpoints to detect any unauthorized changes or access.
  • Employ network monitoring tools to track and analyze unusual activities or access patterns.
  • Educate development and network teams on secure coding practices, particularly regarding header manipulation.
  • Conduct regular security assessments and incorporate automated vulnerability detection tools in the CI/CD pipelines.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.