CVE-2026-36958 Details
Description
A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random or non-existent endpoints on the web management interface, an attacker can exhaust system resources in the embedded Boa HTTP server. This causes the router web interface to become unresponsive and may require manual reboot to restore normal operation.
A denial-of-service vulnerability exists in the U-SPEED N300 wireless router running firmware version 1.0.0. The issue arises when a large number of concurrent HTTP requests are sent to random or non-existent endpoints on the web management interface. This flood of requests exhausts system resources in the embedded Boa HTTP server, causing the router's web interface to become unresponsive. Users may need to manually reboot the router to restore normal operation.
To address this vulnerability, it is recommended to implement connection rate limiting on the Boa web server, restrict the maximum number of concurrent connections per source IP, and introduce an automatic recovery or watchdog mechanism.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/kirubel-cve/CVE-2026-36958 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| u-speed n300 firmware | 1.0.0 |
CPE
Remediation
| |
| u-speed n300 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 5, 2026 | Initial Analysis | [email protected] |
| Apr 30, 2026 | CVE Modified | CISA-ADP |
| Apr 30, 2026 | New CVE Received | [email protected] |