CVE-2026-7192
A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to cause a denial of service (DoS) and a system reboot via a manipulated HTTP POST request directed at the endpoint ‘/js/common/do_cmd.js’ endpoint containing an excessively long parameter, which overwrites the PC and RA registers.
- Published Sep 29, 2026
- CVSS 9.3 critical
- 0.3% chance of exploitation in the next 30 days (EPSS)