CVE-2026-36738

U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes a UART interface that lacks authentication, authorization, or access control mechanisms. An attacker with physical access to the UART pins can connect to the interface and gain unrestricted access to device functionality.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:u-speed:t18-21k_firmware:1.0:*:*:*:*:*:*:*
cpe:2.3:h:u-speed:t18-21k:-:*:*:*:*:*:*:*

History

30 Jun 2026, 19:02

Type Values Removed Values Added
First Time U-speed
U-speed t18-21k Firmware
U-speed t18-21k
References () https://github.com/N0tMilk/vulnerability-research - () https://github.com/N0tMilk/vulnerability-research - Third Party Advisory
References () https://github.com/N0tMilk/vulnerability-research/tree/main/IoT/CVE-2026-36738 - () https://github.com/N0tMilk/vulnerability-research/tree/main/IoT/CVE-2026-36738 - Exploit, Third Party Advisory
CPE cpe:2.3:o:u-speed:t18-21k_firmware:1.0:*:*:*:*:*:*:*
cpe:2.3:h:u-speed:t18-21k:-:*:*:*:*:*:*:*

14 May 2026, 15:16

Type Values Removed Values Added
References () https://github.com/N0tMilk/vulnerability-research/tree/main/IoT/CVE-2026-36738 - () https://github.com/N0tMilk/vulnerability-research/tree/main/IoT/CVE-2026-36738 -
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8

13 May 2026, 16:27

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 16:16

Updated : 2026-06-30 19:02


NVD link : CVE-2026-36738

Mitre link : CVE-2026-36738

CVE.ORG link : CVE-2026-36738


JSON object : View

Products Affected

u-speed

  • t18-21k_firmware
  • t18-21k
CWE
CWE-284

Improper Access Control