Executive brief
The U-SPEED AC1200 Gigabit Wi-Fi Router is a networking device used to provide internet connectivity. A security flaw in its time synchronization settings allows an authorized administrator to run unauthorized system commands. This could lead to a complete takeover of the device, allowing an attacker to monitor network traffic, steal credentials, or disrupt internet service.
Technical details
A command injection vulnerability exists in the /api/system/ntp endpoint of the U-SPEED AC1200 (T18-21K) router firmware V1.0. The application fails to properly sanitize user-supplied input in the 'ntpSrv1' parameter before passing it to a system shell. An authenticated attacker with administrative privileges can use shell metacharacters (e.g., '&') to execute arbitrary operating system commands as root. This can be used to access sensitive files like /etc/passwd or establish persistence. No official patch is currently noted in the advisory, though remediation should involve input validation and avoiding shell execution functions.
Affected products
- U-SPEED AC1200 Gigabit Wi-Fi Router (T18-21K) V1.0
Timeline
- 2026-05-13: disclosed
- 2026-05-13: advisory