Executive brief
A security vulnerability exists in the Dbit N300 T1 Pro wireless router, which is used to provide internet connectivity and manage local network settings. An attacker can trick a logged-in administrator into visiting a malicious website that silently sends commands to the router. This could allow the attacker to change the Wi-Fi name and password, modify network settings, or take full control of the device's configuration.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router running firmware V1.0.0. The device fails to implement anti-CSRF tokens or validate Origin/Referer headers for sensitive administrative API endpoints, such as /api/setWlan, /api/setWan, and /api/setSystem. An unauthenticated remote attacker can craft a malicious webpage that, when visited by an authenticated administrator, leverages the browser's automatic inclusion of session cookies to execute forged POST requests. Successful exploitation allows the attacker to modify wireless settings (SSID/password), WAN configurations, or achieve full device takeover. As of the disclosure date, no official patch has been confirmed by the vendor.
Affected products
- Dbit N300 T1 Pro Firmware 1.0.0
Timeline
- 2026-04-29: disclosed: Vulnerability discovered and reported to MITRE
- 2026-04-30: advisory: NVD published the CVE record