CVE-2026-26048

HIGH

USR-W610 < 3.1.1.0 - Unauthenticated Denial of Service via Forged Management Frames

Title source: llm
STIX 2.1

Description

The Wi-Fi router is vulnerable to de-authentication attacks due to the absence of management frame protection, allowing forged deauthentication and disassociation frames to be broadcast without authentication or encryption. An attacker can use this to cause unauthorized disruptions and create a denial-of-service condition.

Scores

CVSS v3 7.5
EPSS 0.0026
EPSS Percentile 17.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
Jinan USR IOT Technology Limited (PUSR)/USR-W610 < 3.1.1.0
Published Feb 20, 2026
Tracked Since Feb 21, 2026