---
id: CVE-2026-36741
title: >-
  U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to
  Command Injection
summary: >-
  U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to
  Command Injection. The Network Time Protocol (NTP) configuration interface
  does not properly sanitize user-supplied input. An authenticated user with
  permission t…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-77
vendor: u-speed
product: t18-21k_firmware
affected:
  - t18-21k_firmware = 1.0
published: '2026-05-13'
updated: '2026-06-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-36741'
references:
  - url: 'https://github.com/N0tMilk/vulnerability-research'
    label: cve@mitre.org
  - url: >-
      https://github.com/N0tMilk/vulnerability-research/tree/main/IoT/CVE-2026-36741
    label: cve@mitre.org
  - url: >-
      https://github.com/N0tMilk/vulnerability-research/tree/main/IoT/CVE-2026-36741
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.0209
epssPercentile: 0.80792
ingestedAt: '2026-07-01T09:50:45.585Z'
---

## Overview

U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol (NTP) configuration interface does not properly sanitize user-supplied input. An authenticated user with permission to configure NTP settings can inject arbitrary system commands through crafted input fields. These commands are executed with elevated privileges, leading to potential full system compromise.

## Affected

- `t18-21k_firmware = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
