A vulnerability was found in decolua 9router up to 0.4.59. It has been declared as very critical. Affected by this vulnerability is the function
child_process.spawn of the component MCP Plugin Registration. Executing a manipulation can lead to use of default password.
This vulnerability is tracked as CVE-2026-63732. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.