OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-7192

CRITICAL · CVSS 9.3 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows authenticated attackers to exploit an excessively long parameter in an HTTP POST request to the '/js/common/do_cmd.js' endpoint, leading to denial of service and system reboot. This critical vulnerability (CVSS 9.3) poses significant risks to network availability and should be prioritized by organizations using this device to mitigate potential disruptions.

CVE
CVE-2026-7192
Severity
CRITICAL
CVSS
9.3
EPSS
0.26%

Original NVD Description

A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to cause a denial of service (DoS) and a system reboot via a manipulated HTTP POST request directed at the endpoint ‘/js/common/do_cmd.js’ endpoint containing an excessively long parameter, which overwrites the PC and RA registers.