Junglewise Threat Intelligence

CVE-2025-65427: Dbit N300 T1 Pro missing rate limiting in login API

CVE-2025-65427 · Severity: medium · CVSS 6.5 · Published 2025-12-16

Technologies: Dbitnet Dbit N300 T1 Pro Firmware, Dbitnet Dbit N300 T1 Pro. Vendors: Dbitnet.

Executive brief

The Dbit N300 T1 Pro is a wireless Wi-Fi router used for home and small office networking. A security flaw in its login system allows an attacker to repeatedly guess passwords without being blocked or slowed down. If successful, an attacker could gain full administrative control over the router, allowing them to change network settings, redirect internet traffic, or install malicious firmware.

Technical details

A vulnerability classified as Improper Restriction of Excessive Authentication Attempts (CWE-307) exists in the Dbit N300 T1 Pro router firmware version V1.0.0. The /api/login endpoint does not implement rate limiting or account lockout mechanisms for failed authentication attempts. A remote, unauthenticated attacker can exploit this by sending automated HTTP POST requests to guess administrative credentials. Successful exploitation allows for a complete administrative takeover, enabling the attacker to modify DNS settings, change configurations, or perform unauthorized firmware updates. A proof-of-concept using standard HTTP tools has been disclosed.

Affected products

  • Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0

Timeline

  • 2025-12-16: disclosed
  • 2025-12-16: advisory

References

Related threats