cvedb.io
CVE-2026-36958
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2026-04-30T15:16:22.963 · Last modified 2026-06-17T10:41:25.870

Summary

A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random or non-existent endpoints on the web management interface, an attacker can exhaust system resources in the embedded Boa HTTP server. This causes the router web interface to become unresponsive and may require manual reboot to restore normal operation.

Affected products

u-speed — n300_firmware

Does this affect you?

Add your gear to cvedb and we'll alert you only when u-speed ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.