Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-36959 Details

Description

U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attacker on the local network to perform unlimited authentication attempts, enabling brute-force attacks against the administrator account and potential unauthorized access to the router management interface.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://github.com/kirubel-cve/CVE-2026-36959 CISA-ADPExploitThird Party Advisory
https://github.com/kirubel-cve/CVE-2026-36959 [email protected]ExploitThird Party Advisory

Weakness Enumeration

CWE-IDCWE NameSource
CWE-307Improper Restriction of Excessive Authentication AttemptsCISA-ADP

Affected Products

ProductVersions
u-speed n300 firmware
1.0.0

CPE

  • cpe:2.3:o:u-speed:n300_firmware:1.0.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
u-speed n300
All versions

CPE

  • cpe:2.3:h:u-speed:n300:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-36959
NVD Published Date:
Apr 30, 2026
NVD Last Modified:
Jul 5, 2026
Source:
[email protected]
CVE-2026-36959 Details - Not Deferred