---
id: CVE-2026-36738
title: >-
  U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to
  Incorrect Access Control
summary: >-
  U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to
  Incorrect Access Control. The device exposes a UART interface that lacks
  authentication, authorization, or access control mechanisms. An attacker with
  physical ac…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-284
vendor: u-speed
product: t18-21k_firmware
affected:
  - t18-21k_firmware = 1.0
published: '2026-05-13'
updated: '2026-06-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-36738'
references:
  - url: 'https://github.com/N0tMilk/vulnerability-research'
    label: cve@mitre.org
  - url: >-
      https://github.com/N0tMilk/vulnerability-research/tree/main/IoT/CVE-2026-36738
    label: cve@mitre.org
  - url: >-
      https://github.com/N0tMilk/vulnerability-research/tree/main/IoT/CVE-2026-36738
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00326
epssPercentile: 0.22987
ingestedAt: '2026-07-01T09:50:45.569Z'
---

## Overview

U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes a UART interface that lacks authentication, authorization, or access control mechanisms. An attacker with physical access to the UART pins can connect to the interface and gain unrestricted access to device functionality.

## Affected

- `t18-21k_firmware = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
