Vulnerability Description
An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not implement rate limiting to /api/login allowing attackers to brute force password enumerations.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dbitnet | Dbit N300 T1 Pro Firmware | 1.0.0 |
| Dbitnet | Dbit N300 T1 Pro | - |
Related Weaknesses (CWE)
References
- http://dbit.comNot Applicable
- http://shenzhen.comBroken Link
- https://github.com/kirubel-cve/CVE-2025-65427ExploitThird Party Advisory
FAQ
What is CVE-2025-65427?
CVE-2025-65427 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not implement rate limiting to /api/login allowing attackers to brute force password enumer...
How severe is CVE-2025-65427?
CVE-2025-65427 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-65427?
Check the references section above for vendor advisories and patch information. Affected products include: Dbitnet Dbit N300 T1 Pro Firmware, Dbitnet Dbit N300 T1 Pro.