CVE-2026-7674
Shenzhen Libituo Technology LBT-T300-HW1 Web Management start_single_service buffer overflow
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
A flaw has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1.2.8. This issue affects the function start_single_service of the component Web Management Interface. Executing a manipulation of the argument vpn_pptp_server/vpn_l2tp_server can lead to buffer overflow. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.
| CWE | CWE-120 CWE-119 |
| Vendor | shenzhen libituo technology |
| Product | lbt-t300-hw1 |
| Published | May 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for shenzhen libituo technology lbt-t300-hw1
Be the first to know when new high vulnerabilities affecting shenzhen libituo technology lbt-t300-hw1 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Shenzhen Libituo Technology / LBT-T300-HW1
1.2.0 1.2.1 1.2.2 1.2.3 1.2.4 1.2.5 1.2.6 1.2.7 1.2.8
References
Credits
๐ kunlun (VulDB User) VulDB CNA Team