CVE-2026-36738
Last modified
CVE-2026-36738 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes a UART interface that lacks authentication, authorization, or access control mechanisms. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes a UART interface that lacks authentication, authorization, or access control mechanisms. An attacker with physical access to the UART pins can connect to the interface and gain unrestricted access to device functionality.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| U-Speed | T18-21k Firmware | 1.0 |
References
- https://github.com/N0tMilk/vulnerability-researchThird Party Advisory
- https://github.com/N0tMilk/vulnerability-research/tree/main/IoT/CVE-2026-36738Exploit, Third Party Advisory
- https://github.com/N0tMilk/vulnerability-research/tree/main/IoT/CVE-2026-36738Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-36738?
How severe is CVE-2026-36738?
How do I fix CVE-2026-36738?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-36725A markdown based cross-site scripting (XSS) vulnerability in…6.1
- CVE-2026-36726An arbitrary file deletion vulnerability in the /api/delete-…5.3
- CVE-2026-36727An insecure authentication vulnerability in the /api/social-…9.1
- CVE-2026-36728A markdown based cross-site scripting (XSS) vulnerability in…5.4
- CVE-2026-3673An authenticated attacker can store a crafted tag value in _…5.4
- CVE-2026-36734EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection.…8.8
- CVE-2026-3674A vulnerability was found in Freedom Factory dGEN1 up to 202…5.3
- CVE-2026-36741U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is…7.2
- CVE-2026-36742Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. Th…6.8
- CVE-2026-36748RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Si…9
- CVE-2026-3675A vulnerability was determined in Freedom Factory dGEN1 up t…5.3
- CVE-2026-36756A Server-Side Request Forgery (SSRF) in the /plugins/-/insta…5.4
Are you affected by CVE-2026-36738?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
