
Proof-of-concept exploit for CVE-2026-36959, a missing rate limiting vulnerability in U-SPEED Router firmware allowing brute-force attacks on the admin login endpoint.
CVE ID: CVE-2026-36959 Date: 2026-04-29 Discoverer: Kirubel Solomne Vendor: U-SPEED Product: U-SPEED Router Firmware Version: V1.0.0 CWE: CWE-307 - Improper Restriction of Excessive Authentication Attempts
The U-SPEED Router firmware V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attacker on the local network to perform unlimited authentication attempts, enabling brute-force attacks against the administrator account and potential unauthorized access to the router management interface.
CVSS v3.1 Score: 7.5 (High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
| Metric | Value |
|---|---|
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Confidentiality Impact | High |
| Integrity Impact | None |
| Availability Impact | None |
POST /api/login HTTP/1.1
Host: [Router_IP]
Content-Type: application/json
{"username": "admin", "password": "password_guess"}
No throttling or lockout is triggered after repeated failed attempts.
/api/login| Date | Event |
|---|---|
| 2026-04-29 | Vulnerability discovered |
| 2026-04-29 | Reported to MITRE |
| 2026-04-29 | CVE-2026-36959 assigned |
| 2026-04-29 | Public disclosure |