Junglewise Threat Intelligence

CVE-2026-36958: U-SPEED N300 resource exhaustion DoS in Boa HTTP server

CVE-2026-36958 · Severity: high · CVSS 7.5 · Published 2026-04-30

Vendors: U-SPEED.

Executive brief

A denial-of-service vulnerability affects the U-SPEED N300 wireless router, a device used to provide internet connectivity in home or small office environments. By flooding the device with web requests, an attacker can crash the management interface, making it impossible for administrators to change settings or monitor the network. In some cases, this may disrupt general routing services and require a physical manual reboot to restore the device to a working state.

Technical details

A denial-of-service (DoS) vulnerability exists in the U-SPEED N300 router (firmware V1.0.0) due to uncontrolled resource consumption (CWE-400) in the embedded Boa HTTP server. The vulnerability is triggered by sending a high volume of concurrent HTTP requests to arbitrary or non-existent endpoints on the web management interface. This resource exhaustion causes the web server to become unresponsive and may impact broader routing functionality. The attack can be launched remotely over the network without authentication or user interaction. A manual reboot is typically required to restore service, as the device lacks sufficient rate limiting or automated recovery mechanisms for this condition.

Affected products

  • U-SPEED N300 1.0.0

Timeline

  • 2026-04-29: disclosed: Vulnerability discovered and reported to MITRE
  • 2026-04-30: advisory: NVD published the CVE record

References

Related threats