Dbit N300 T1 Pro Wireless Router Authentication Rate Limiting Vulnerability

Vulnerability

A vulnerability exists in the Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router running firmware version V1.0.0. The router's login API lacks proper rate limiting, enabling remote attackers to perform brute-force or credential-stuffing attacks. This flaw could lead to unauthorized administrative access, allowing attackers to change configurations, modify DNS settings, or upload new firmware.

Impact

Exploitation of this vulnerability could result in unauthorized administrative access to the router, allowing attackers to make configuration changes, alter DNS settings, or upload firmware updates.

Reproduction

The vulnerability can be reproduced by sending automated HTTP POST requests to the '/api/login' endpoint with varying password guesses. The absence of rate limiting can be verified by observing the server's response, which includes a session token even after multiple failed login attempts.

Added: Dec 16, 2025, 6:54 PM
Updated: Dec 16, 2025, 9:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
1.4
threat
6.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.