← Back to CVE search

CVE-2026-36960

U-SPEED N300 Rounter

Description

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints. If an authenticated administrator visits the malicious webpage, the victim-s browser automatically includes the valid session cookie in the request, allowing the router to process the request as a legitimate administrative action.

CVSS 8.8EPSS 0.173%Risk 0.89
View source
Published
2026-04-30 16:16:43
Affected versions
<1.0.1,==1.0.0
Type
Firmware
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H