A critical vulnerability in 9Router and MCP platforms (versions 0.4.30 through 0.4.37) enables unauthenticated remote code execution via unprotected API routes. The src/proxy.js middleware failed to secure /api/cli-tools/* and /api/mcp/* endpoints, allowing attackers to register custom plugins through src/app/api/cli-tools/cowork-settings/route.js and execute commands via the MCP bridge. This exposure permits full system compromise without authentication requirements. The CVSS score of 10.0 reflects the severity of unrestricted remote code execution capabilities. All users of affected versions are strongly advised to upgrade to 0.4.37 immediately, where the vulnerability is resolved through endpoint access controls. Organizations leveraging these platforms for network management or AI routing should prioritize patching to eliminate exploitation risks. No workarounds exist for this flaw, which bypasses fundamental authentication safeguards. The vulnerability impacts both platform integrity and data confidentiality, necessitating urgent remediation.