CVE-2026-36956
Last modified
CVE-2026-36956 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to implement proper CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to implement proper CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints such as /api/setWlan. If an authenticated administrator visits the malicious webpage, the victim's browser automatically includes the valid session cookie in the request, allowing the router to process the request as a legitimate administrative action.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dbitnet | Dbit N300 T1 Pro Firmware | 1.0.0 |
References
- https://github.com/kirubel-cve/CVE-2026-36956Exploit, Third Party Advisory
- https://github.com/kirubel-cve/CVE-2026-36956Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-36956?
How severe is CVE-2026-36956?
How do I fix CVE-2026-36956?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-36946Sourcecodester Computer and Mobile Repair Shop Management Sy…2.7
- CVE-2026-36947Sourcecodester Computer and Mobile Repair Shop Management Sy…2.7
- CVE-2026-36948Sourcecodester Online Thesis Archiving System v1.0 is vulner…7.3
- CVE-2026-3695A vulnerability has been found in SourceCodester Modern Imag…6.5
- CVE-2026-36950Sourcecodester Online Thesis Archiving System v1.0 is vulner…2.7
- CVE-2026-36952Sourcecodester Online Thesis Archiving System v1.0 is vulner…2.7
- CVE-2026-36957Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is …7.5
- CVE-2026-36958A denial-of-service vulnerability exists in the U-SPEED N300…7.5
- CVE-2026-36959U-SPEED N300 router V1.0.0 does not implement rate limiting …7.5
- CVE-2026-3696A vulnerability was found in Totolink N300RH 6..1c.1353_B201…9.8
- CVE-2026-36960A Cross-Site Request Forgery (CSRF) vulnerability exists in …8.8
- CVE-2026-36962SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthe…7.3
Are you affected by CVE-2026-36956?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
