Junglewise Threat Intelligence

CVE-2026-36960: U-SPEED N300 Router CSRF in web management interface

CVE-2026-36960 · Severity: high · CVSS 8.8 · Published 2026-04-30

Vendors: U-SPEED.

Executive brief

A security vulnerability exists in the U-SPEED N300 router, a device used to provide wireless internet connectivity. An attacker can trick a logged-in administrator into visiting a malicious website, which then silently sends commands to the router. This could allow an attacker to change the Wi-Fi password, take over the network, or disable the device entirely.

Technical details

The U-SPEED N300 Router V1.0.0 firmware is vulnerable to Cross-Site Request Forgery (CSRF) because its web management interface lacks protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation. The vulnerability affects administrative API endpoints including /api/setWlan and /api/telnet. An unauthenticated remote attacker can exploit this by crafting a malicious webpage that sends forged POST requests to these endpoints. If an authenticated administrator interacts with the malicious page, their browser will automatically include session cookies, leading to unauthorized configuration changes, such as modifying Wi-Fi settings or enabling Telnet. As of the disclosure, no official patch has been confirmed, though remediation involves implementing anti-CSRF tokens and SameSite cookie attributes.

Affected products

  • U-SPEED N300 Router V1.0.0

Timeline

  • 2026-04-29: disclosed: Vulnerability discovered and public disclosure occurred.
  • 2026-04-30: advisory: NVD published the CVE record.

References

Related threats