CVE-2026-36957 Details
Description
Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating a high-volume flood of HTTP GET requests to non-existent URIs, an attacker can exhaust critical system resources, including file descriptors and memory buffers. This results in a kernel deadlock or system hang that disables the web management portal and all routing capabilities.
A denial-of-service vulnerability has been identified in the Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router, running firmware version 1.0.0. The issue arises in the boa web server URI handler, where an attacker can send a high volume of HTTP GET requests to non-existent URIs. This flood of requests exhausts critical system resources, such as file descriptors and memory buffers, leading to a kernel deadlock or system hang. As a result, the web management portal becomes unresponsive, and all routing capabilities are disabled.
To address this vulnerability, it is recommended to implement connection rate limiting on the boa web server, add a watchdog timer to recover from deadlock states, and limit the maximum number of concurrent connections per IP address.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/kirubel-cve/CVE-2026-36957 | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/kirubel-cve/CVE-2026-36957 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| dbitnet dbit n300 t1 pro firmware | 1.0.0 |
CPE
Remediation
| |
| dbitnet dbit n300 t1 pro | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 5, 2026 | Initial Analysis | [email protected] |
| Apr 30, 2026 | CVE Modified | CISA-ADP |
| Apr 30, 2026 | New CVE Received | [email protected] |