Junglewise Threat Intelligence

CVE-2026-36957: Dbit N300 T1 Pro denial of service in Boa web server

CVE-2026-36957 · Severity: high · CVSS 7.5 · Published 2026-04-30

Technologies: Dbitnet Dbit N300 T1 Pro Firmware, Dbitnet Dbit N300 T1 Pro. Vendors: Dbitnet.

Executive brief

The Dbit N300 T1 Pro Wi-Fi router is vulnerable to a denial-of-service attack that can completely disable the device. By flooding the router's web management interface with requests for non-existent pages, an attacker can cause the device to freeze or crash. This results in a total loss of internet connectivity for all connected users and requires a manual physical reboot to restore service.

Technical details

A vulnerability in the Boa web server URI handler of the Dbit N300 T1 Pro router (v1.0.0) allows for uncontrolled resource consumption (CWE-400). An unauthenticated remote attacker can initiate a high-volume flood of HTTP GET requests targeting non-existent URIs. This activity exhausts critical system resources, specifically file descriptors and memory buffers, leading to a kernel deadlock or system hang. The exploit results in the failure of both the web management portal and all core routing functions. Recovery requires a manual hardware power cycle. No official patch is currently noted, though remediation suggests implementing rate limiting and watchdog timers.

Affected products

  • Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router 1.0.0

Timeline

  • 2026-04-29: disclosed: Vulnerability discovered and reported to MITRE
  • 2026-04-30: advisory: NVD published the CVE record

References

Related threats