ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-36741
+1 in the same advisory: …36738
U-SPEED AC1200 Gigabit Wi-Fi Router (Model:

U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol (NTP) configuration interface does not properly sanitize user-supplied input. An authenticated user with permission to configure NTP settings can inject arbitrary system commands through crafted input fields. These commands are executed with elevated privileges, leading to potential full system compromise.

NVD description · AI analysis pending
7.2
group max
2% PoC
  • u-speed t18-21k firmware
CVE-2026-36959
+1 in the same advisory: …36958
U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint.

U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attacker on the local network to perform unlimited authentication attempts, enabling brute-force attacks against the administrator account and potential unauthorized access to the router management interface.

NVD description · AI analysis pending
7.5<1% PoC
  • u-speed n300 firmware