CVE-2026-36956

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to implement proper CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints such as /api/setWlan. If an authenticated administrator visits the malicious webpage, the victim's browser automatically includes the valid session cookie in the request, allowing the router to process the request as a legitimate administrative action.
References
Link Resource
http://dbit.com Not Applicable
https://github.com/kirubel-cve/CVE-2026-36956 Exploit Third Party Advisory
https://github.com/kirubel-cve/CVE-2026-36956 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dbitnet:dbit_n300_t1_pro_firmware:1.0.0:*:*:*:*:*:*:*
cpe:2.3:h:dbitnet:dbit_n300_t1_pro:-:*:*:*:*:*:*:*

History

05 May 2026, 00:09

Type Values Removed Values Added
First Time Dbitnet dbit N300 T1 Pro
Dbitnet
Dbitnet dbit N300 T1 Pro Firmware
CPE cpe:2.3:o:dbitnet:dbit_n300_t1_pro_firmware:1.0.0:*:*:*:*:*:*:*
cpe:2.3:h:dbitnet:dbit_n300_t1_pro:-:*:*:*:*:*:*:*
References () http://dbit.com - () http://dbit.com - Not Applicable
References () https://github.com/kirubel-cve/CVE-2026-36956 - () https://github.com/kirubel-cve/CVE-2026-36956 - Exploit, Third Party Advisory

30 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-30 15:16

Updated : 2026-05-05 00:09


NVD link : CVE-2026-36956

Mitre link : CVE-2026-36956

CVE.ORG link : CVE-2026-36956


JSON object : View

Products Affected

dbitnet

  • dbit_n300_t1_pro
  • dbit_n300_t1_pro_firmware
CWE
CWE-352

Cross-Site Request Forgery (CSRF)