Executive brief
The Dbit N300 T1 Pro is a wireless Wi-Fi router used for home and small office networking. A security flaw in its login system allows an attacker to repeatedly guess passwords without being blocked or slowed down. If successful, an attacker could gain full administrative control over the router, allowing them to change network settings, redirect internet traffic, or install malicious firmware.
Technical details
A vulnerability classified as Improper Restriction of Excessive Authentication Attempts (CWE-307) exists in the Dbit N300 T1 Pro router firmware version V1.0.0. The /api/login endpoint does not implement rate limiting or account lockout mechanisms for failed authentication attempts. A remote, unauthenticated attacker can exploit this by sending automated HTTP POST requests to guess administrative credentials. Successful exploitation allows for a complete administrative takeover, enabling the attacker to modify DNS settings, change configurations, or perform unauthorized firmware updates. A proof-of-concept using standard HTTP tools has been disclosed.
Affected products
- Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0
Timeline
- 2025-12-16: disclosed
- 2025-12-16: advisory