Junglewise Threat Intelligence

CVE-2026-36738: U-SPEED AC1200 Router unauthenticated UART interface access

CVE-2026-36738 · Severity: medium · CVSS 6.8 · Published 2026-05-13

Vendors: U-SPEED.

Executive brief

The U-SPEED AC1200 Wi-Fi router contains a security flaw where its internal hardware communication port is left unprotected. An individual with physical access to the device can bypass all security measures by connecting directly to the internal circuit board. This allows for complete control over the router, including the ability to steal passwords, modify settings, or install malicious software.

Technical details

The U-SPEED AC1200 (T18-21K) router exposes a Universal Asynchronous Receiver-Transmitter (UART) interface on its internal PCB that lacks any authentication or authorization mechanisms. An attacker with physical access to the device can open the enclosure and use a USB-to-UART adapter to interface with the hardware. This provides direct, unauthenticated access to the system console, bootloader, and operating system shell. From this position, an attacker can extract configuration files, modify firmware, or execute arbitrary commands with root-level privileges. No software-based fix is currently noted, though hardware-level mitigations like disabling the port or requiring console passwords are recommended.

Affected products

  • U-SPEED AC1200 Gigabit Wi-Fi Router (T18-21K) 1.0

Timeline

  • 2026-05-13: disclosed: Initial disclosure via MITRE and NVD
  • 2026-05-13: advisory

References

Related threats