Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-36959 — Proof-of-concept exploit for CVE-2026-36959, a missing rate limiting vulnerability in U-SPEED Router firmware allowing brute-force attacks on the admin login endpoint. | Kitploit
Tools/GitHubGitHub/kirubel-cve/cve-2026-36959
Vulnerability AnalysisExploitationWeb SecurityPenetration TestingAuthentication
GitHubkirubel-cve/cve-2026-36959

CVE-2026-36959

Proof-of-concept exploit for CVE-2026-36959, a missing rate limiting vulnerability in U-SPEED Router firmware allowing brute-force attacks on the admin login endpoint.

View Repository
195 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-36959: Missing Rate Limiting on Login Endpoint

CVE ID: CVE-2026-36959 Date: 2026-04-29 Discoverer: Kirubel Solomne Vendor: U-SPEED Product: U-SPEED Router Firmware Version: V1.0.0 CWE: CWE-307 - Improper Restriction of Excessive Authentication Attempts


Description

The U-SPEED Router firmware V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attacker on the local network to perform unlimited authentication attempts, enabling brute-force attacks against the administrator account and potential unauthorized access to the router management interface.


CVSS Score

CVSS v3.1 Score: 7.5 (High) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

MetricValue
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactNone
Availability ImpactNone

Proof of Concept

POST /api/login HTTP/1.1
Host: [Router_IP]
Content-Type: application/json

{"username": "admin", "password": "password_guess"}

No throttling or lockout is triggered after repeated failed attempts.


Impact

  • Unauthorized administrative access
  • Full router configuration takeover
  • Network compromise

Remediation

  • Implement rate limiting on /api/login
  • Add account lockout after repeated failed attempts
  • Implement exponential backoff or CAPTCHA

Disclosure Timeline

DateEvent
2026-04-29Vulnerability discovered
2026-04-29Reported to MITRE
2026-04-29CVE-2026-36959 assigned
2026-04-29Public disclosure

References

  • MITRE CVE-2026-36959
  • CWE-307
  • Vendor Website
Download Tool