{"id":"CVE-2026-7192","title":"A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to cause a denial of service (DoS) and a system reboot via a manipulated HTTP POST request directed at the endpoint ‘/j…","summary":"A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to cause a denial of service (DoS) and a system reboot via a manipulated HTTP POST request directed at the endpoint ‘/j…","severity":"critical","cvss":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-121"],"vendor":"Shenzhen Dbit Network Equipment","product":"T-CPE301K 4G Mini WiFi Router","affected":["t-cpe301k_4g_mini_wifi_router < 29/09/2026"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T15:17:28.370","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7192","references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-t-cpe301k-4g-mini-wifi-router-shenzhen-dbit","label":"cve-coordination@incibe.es"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-29T14:37:26.485761Z"},"cvssSource":"cna","ingestedAt":"2026-09-29T12:33:37.300Z","slug":"CVE-2026-7192","body":"## Overview\n\nA stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to cause a denial of service (DoS) and a system reboot via a manipulated HTTP POST request directed at the endpoint ‘/js/common/do_cmd.js’ endpoint containing an excessively long parameter, which overwrites the PC and RA registers.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":51,"depthScoreParts":{"impact":51.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}