Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment

Posted date 29/09/2026
Identificador
INCIBE-2026-671
Importance
5 - Critical
Affected Resources

T-CPE301K 4G Mini WiFi Router (Dbit).

Description

INCIBE has coordinated the publication of two vulnerabilities – one of critical severity and one of high severity – affecting the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment, a portable router that uses a 4G SIM card to create a Wi-Fi network. The vulnerabilities were discovered by Marcos González Sanz (mrk).

These vulnerabilities have been assigned the following codes, CVSS v4.0 base score, CVSS vector and CWE vulnerability type for each vulnerability:

  • CVE-2026-7192: CVSS v4.0: 9.3 | CVSS AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | CWE-121
  • CVE-2026-7193: CVSS v4.0: 8.6 | CVSS AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | CWE-798
Solution

No solution has been reported as yet.

Detail
  • CVE-2026-7192: a stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to cause a denial of service (DoS) and a system reboot via a manipulated HTTP POST request directed at the endpoint ‘/js/common/do_cmd.js’ endpoint containing an excessively long parameter, which overwrites the PC and RA registers.
  • CVE-2026-7193: a vulnerability relating to the use of predefined credentials in the Dbit T-CPE301K 4G WiFi mini-router allows an attacker connected to the same network to gain full root access to the device via the Telnet service (port 23) using static credentials.
CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-7192 Crítica No Shenzhen Dbit Network Equipment
CVE-2026-7193 Crítica No Shenzhen Dbit Network Equipment
References list
Etiquetas