Dbit N300 T1 Pro Wireless Router Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router, running firmware version 1.0.0. The issue arises in the boa web server URI handler, where an attacker can send a high volume of HTTP GET requests to non-existent URIs. This flood of requests exhausts critical system resources, such as file descriptors and memory buffers, leading to a kernel deadlock or system hang. As a result, the web management portal becomes unresponsive, and all routing capabilities are disabled.

Impact

Exploitation of this vulnerability causes a complete loss of the web management interface and disrupts all routing functions, leading to network downtime for connected devices. The router requires a manual reboot to restore normal operation.

Reproduction

The vulnerability can be reproduced by sending a large number of HTTP GET requests to non-existent URIs on the router's web server. This can be done using a script that automates the process, such as one written in Python that uses the requests library to flood the server with requests. The router's web interface will become unresponsive, and all routing capabilities will be disrupted, causing network downtime for connected devices.

Remediation

To address this vulnerability, it is recommended to implement connection rate limiting on the boa web server, add a watchdog timer to recover from deadlock states, and limit the maximum number of concurrent connections per IP address.

Added: Apr 30, 2026, 3:32 PM
Updated: Apr 30, 2026, 3:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.2
remediation
0.0
relevance
7.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.