CVE-2026-79588 Details
Description
U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.
A vulnerability exists in the U-speed N300 WIFI4 router, model T1 Pro, version 1.0.0, due to the cleartext transmission of administration credentials over HTTP. This flaw allows anyone connected to the same local network to intercept and read the sensitive information. The vulnerability is categorized as credential sniffing, with a local access attack vector.
Users are advised to update the router's firmware to a version that addresses this vulnerability, if available. If no update is possible, consider using a different router model that does not have this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/milkinit/cve-disclosures/tree/main/IoT/CVE-2026-79588 | CISA-ADP | ExploitRemedyTechnical Description |
| https://github.com/milkinit/cve-disclosures/tree/main/IoT/CVE-2026-79588 | [email protected] | ExploitRemedyTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| U-speed N300 WIFI4 T1 Pro | 1.0.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |
Volerion