---
id: CVE-2025-71383
title: >-
  Dbit WIFI4 N300 1.0.0 devices allow the management interface to be crashed via
  a request (from the local Wi-Fi network) that lacks a /api/login username or
  password field
summary: >-
  Dbit WIFI4 N300 1.0.0 devices allow the management interface to be crashed via
  a request (from the local Wi-Fi network) that lacks a /api/login username or
  password field. This occurs because of an error in a JSON parser.
severity: none
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T17:17:10.953'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-71383'
references:
  - url: >-
      https://www.klogixsecurity.com/scorpion-labs-blog/anatomy-of-an-iot-exploit-from-hands-on-to-rce-folie-a-deux
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T17:09:22.187Z'
---

## Overview

Dbit WIFI4 N300 1.0.0 devices allow the management interface to be crashed via a request (from the local Wi-Fi network) that lacks a /api/login username or password field. This occurs because of an error in a JSON parser.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
