← Voltar à pesquisa de CVEs

CVE-2026-36960

U-SPEED N300 Rounter

Descrição

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints. If an authenticated administrator visits the malicious webpage, the victim-s browser automatically includes the valid session cookie in the request, allowing the router to process the request as a legitimate administrative action.

CVSS 8.8EPSS 0.173%Risco 0.89
Ver fonte
Publicação
2026-04-30 16:16:43
Versões afetadas
<1.0.1,==1.0.0
Tipo
Firmware
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H