CVE-2026-7674Disclosure

MEDIUMCVSS 8.7 · HIGH

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A flaw has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1.2.8. This issue affects the function start_single_service of the component Web Management Interface. Executing a manipulation of the argument vpn_pptp_server/vpn_l2tp_server can lead to buffer overflow. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-05-03); latest day: 3
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01223Mentions · 2026-05-03: 3Mentions · 2026-05-15: 1Mentions · 2026-05-31: 3Active Exploitation · 2026-05-03: 1Patch / Workaround · 2026-05-03: 1Patch / Workaround · 2026-05-31: 1Technical Details · 2026-05-03: 2Technical Details · 2026-05-15: 1Technical Details · 2026-05-31: 305-0305-1505-31
Signal classification3 categories
Disclosure
571.4%
Active Exploitation
114.3%
General
114.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-033
Active Exploitation1Disclosure1General1
2026-05-151
Disclosure1
2026-05-313
Disclosure3
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    Shenzhen Libituo Technology's LBT-T300-HW1 network device ships with two unauthenticated remote buffer overflow vulnerabilities (CVE-2026-7674, CVE-2026-7675, both CVSS 8.8), disclosed May 3, 2026. The vendor has not responded. No patch is available. Remote attackers need…

    Post summary

    Shenzhen Libituo Technology’s LBT‑T300‑HW1 device has two newly disclosed unauthenticated remote buffer overflow vulnerabilities (CVE-2026-7674, CVE-2026-7675, CVSS 8.8). The vendor has not responded and no patch is currently available.

    1000046
    236 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-7674 and CVE-2026-7675 follow identical exploitation patterns: an unauthenticated attacker can manipulate specific arguments (vpnpptpserver and vpnl2tpserver) in the startsingleservice() function, sending malformed data that overflows the allocated buffer. The…

    Post summary

    The passage describes how CVE‑2026‑7674 and CVE‑2026‑7675 exploit a buffer overflow via specific arguments, but provides no PoC, exploitation tool, patch, or evidence of active attacks.

    1000034
    236 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Device That Never Got Patched: Shenzhen Libituo''s Dual CVSS 8.8 Buffer Overflow Crisis. Shenzhen Libituo Technology's LBT-T300-HW1 network device ships with two unauthenticated remote buffer overflow vulnerabilities CVE-2026-7674, CVE-2026-7675, both CVSS 8.8,…

    Post summary

    The post announces that Shenzhen Libituo's LBT‑T300‑HW1 device contains two unauthenticated remote buffer overflow vulnerabilities (CVE‑2026‑7674 and CVE‑2026‑7675) with CVSS scores of 8.8.

    1000042
    236 followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    A high-severity buffer overflow flaw (CVE-2026-7674) affects Shenzhen Libituo LBT-T300-HW1 devices, exploitable remotely via VPN server parameters. Mohawk Valley SMBs using this device should assess risk and mitigate where possible.

    Post summary

    The tweet announces a high‑severity buffer overflow vulnerability (CVE‑2026‑7674) in Shenzhen Libituo LBT‑T300‑HW1 devices, noting it can be exploited remotely via VPN parameters but provides no PoC, exploit code, or patch details, and advises SMBs to assess risk.

    0000055
    80 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    🔴 CVE-2026-7674 in Shenzhen Libituo's LBT-T300-HW1 is being exploited now—hackers can execute arbitrary code through a buffer overflow. Patch immediately to avoid system compromise. #NerdieNews #CyberSecurity #InfoSec #Vulnerability #AIPhishing https://t.co/knKJMcX6mC

    Post summary

    The tweet reports that CVE‑2026‑7674 is actively exploited via a buffer overflow, urging immediate patching to prevent arbitrary code execution.

    0000044
    57 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7674 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7674 #CVE-2026-7674 #CVE #High #CyberSecurity #InfoSec https://t.co/ImtfzFdB9g

    Post summary

    A new vulnerability, CVE‑2026‑7674, has been disclosed with a high severity rating, but the tweet provides no further details on exploitation, patches, or technical specifics.

    0000064
    151 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7674 Buffer Overflow in Shenzhen Libituo Technology LBT-T300-HW1 Web Ma... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7674 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    A new buffer overflow vulnerability (CVE‑2026‑7674) has been disclosed for the Shenzhen Libituo Technology LBT‑T300‑HW1 device, but the tweet does not provide any PoC, exploit, patch, or evidence of active exploitation.

    0000046
    4.0K followersView on X

Explore more