CVE-2026-36958
7.5U-SPEED · N300 V1.0.0 wireless router
An unauthenticated denial-of-service vulnerability in the U-SPEED N300 V1.0.0 router allows resource exhaustion of the embedded Boa HTTP server via high-volume concurrent requests.
Executive summary
A critical denial-of-service vulnerability in the U-SPEED N300 V1.0.0 wireless router allows unauthenticated attackers to crash the management interface via resource exhaustion.
Vulnerability
This vulnerability affects the embedded Boa HTTP server, where an unauthenticated attacker can send a large volume of concurrent HTTP requests to arbitrary endpoints, leading to system resource exhaustion and interface unresponsiveness.
Business impact
Successful exploitation results in the loss of availability for the router management interface, requiring a manual reboot to restore functionality. With a CVSS score of 7.5, this high-severity flaw poses a significant operational risk, as attackers can repeatedly disrupt network administration capabilities, potentially facilitating further malicious activities or network downtime.
Remediation
Immediate Action: Restrict access to the router web management interface to trusted internal IP addresses only, as no vendor patch is currently confirmed.
Proactive Monitoring: Monitor network traffic for unusual spikes in concurrent HTTP requests directed at the router management interface.
Compensating Controls: Implement rate limiting on the network perimeter or place the management interface behind a firewall to mitigate high-volume request attacks.
Exploitation status
Public Exploit Available: Yes — a public proof-of-concept exists, attributed to the research write-up referenced in the CVE record.
Analyst recommendation
Given the availability of a proof-of-concept and the ease of exploitation, organizations using the U-SPEED N300 V1.0.0 should prioritize hardening the management interface immediately. Since a patch is not yet confirmed, limiting administrative access to authorized management segments is the most effective method to reduce the attack surface and maintain business continuity.