A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random or non-existent endpoints on the web management interface, an attacker can exhaust system resources in the embedded Boa HTTP server. This causes the router web interface to become unresponsive and may require manual reboot to restore normal operation.
References
| Link | Resource |
|---|---|
| http://u-speed.com | Broken Link |
| https://github.com/kirubel-cve/CVE-2026-36958 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
05 May 2026, 03:00
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
U-speed n300
U-speed n300 Firmware U-speed |
|
| CPE | cpe:2.3:h:u-speed:n300:-:*:*:*:*:*:*:* cpe:2.3:o:u-speed:n300_firmware:1.0.0:*:*:*:*:*:*:* |
|
| References | () http://u-speed.com - Broken Link | |
| References | () https://github.com/kirubel-cve/CVE-2026-36958 - Exploit, Third Party Advisory |
30 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-30 15:16
Updated : 2026-05-05 03:00
NVD link : CVE-2026-36958
Mitre link : CVE-2026-36958
CVE.ORG link : CVE-2026-36958
JSON object : View
Products Affected
u-speed
- n300_firmware
- n300
CWE
CWE-400
Uncontrolled Resource Consumption
