Description
Dbit WIFI4 N300 1.0.0 devices allows administrators (from the local Wi-Fi network) to execute OS commands by leveraging a stack-based buffer overflow via the /api/addStaticDHCP comment field,
Published: 2026-10-06
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A stack-based buffer overflow occurs in the /api/addStaticDHCP comment field, enabling administrators who are connected to the local Wi‑Fi network to execute arbitrary operating system commands on the device. This flaw can lead to full system compromise, granting attackers full control over the affected device.

Affected Systems

Dbit Wi‑Fi4 N300 1.0.0 devices are impacted. No other affected versions are listed.

Risk and Exploitability

The vulnerability is exploitable from the local network, which may be common in home or small‑business environments. Although EPSS data are not available and the flaw is not listed in CISA KEV, the nature of the exploit and its ability to execute arbitrary commands suggest a high likelihood of abuse if the device is reachable. The lack of a public CVSS score underscores the need for caution due to the severity of possible outcomes.

Generated by OpenCVE AI on October 7, 2026 at 06:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Replace or update the device firmware to a version that addresses the buffer overflow.
  • Disable or restrict access to the /api/addStaticDHCP endpoint for local network administrators.
  • Implement network segmentation and restrict administrative access to trusted devices or management networks.

Generated by OpenCVE AI on October 7, 2026 at 06:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Title Stack-Based Buffer Overflow in DHCP API Allows Local Admins to Execute Arbitrary OS Commands
Weaknesses CWE-120

Tue, 06 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description Dbit WIFI4 N300 1.0.0 devices allows administrators (from the local Wi-Fi network) to execute OS commands by leveraging a stack-based buffer overflow via the /api/addStaticDHCP comment field,
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-06T16:57:30.877Z

Reserved: 2026-06-24T00:00:00.000Z

Link: CVE-2025-71384

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-06T17:17:11.090

Modified: 2026-10-06T20:06:12.743

Link: CVE-2025-71384

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T06:30:13Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')