Buffer Overflow Vulnerability in Shenzhen Libituo Technology Product
CVE-2026-7675
Key Information:
- Vendor
Shenzhen Libituo Technology
- Status
- Vendor
- CVE Published:
- 3 May 2026
Badges
What is CVE-2026-7675?
A buffer overflow vulnerability has been identified in the Shenzhen Libituo Technology LBT-T300-HW1 router, specifically within the start_lan function of the /apply.cgi file. This issue arises when user-controlled input is mishandled, allowing remote attackers to manipulate the Channel/ApCliSsid argument. As a result, this can lead to unauthorized access and potential system compromise. The vulnerability has been publicly disclosed, and despite early notification attempts, the vendor has not responded, raising concerns about the risk of exploitation affecting users.
Affected Version(s)
LBT-T300-HW1 1.2.0
LBT-T300-HW1 1.2.1
LBT-T300-HW1 1.2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
