Junglewise Threat Intelligence

CVE-2026-36959: U-SPEED N300 missing rate limiting in /api/login

CVE-2026-36959 · Severity: high · CVSS 7.5 · Published 2026-04-30

Vendors: U-SPEED.

Executive brief

The U-SPEED N300 router fails to limit the number of times a user can attempt to log in to the management interface. This allows an attacker to repeatedly guess the administrator password without being blocked or slowed down. If successful, an attacker could gain full control over the router's settings and the traffic passing through the network.

Technical details

The U-SPEED N300 router firmware version 1.0.0 contains a vulnerability classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts). The /api/login endpoint lacks rate limiting, exponential backoff, or account lockout mechanisms. A network-based attacker can send an unlimited number of POST requests to the authentication API to brute-force administrative credentials. Successful exploitation grants the attacker unauthorized administrative access to the router management interface, potentially leading to full device compromise. As of the advisory date, no official patch has been confirmed, though remediation steps include implementing throttling or CAPTCHA.

Affected products

  • U-SPEED N300 Router 1.0.0

Timeline

  • 2026-04-29: disclosed: Vulnerability discovered and reported to MITRE
  • 2026-04-30: advisory: NVD publication date

References

Related threats