CVE-2026-7675Disclosure

LOWCVSS 7.4 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1.2.8. Impacted is the function start_lan of the file /apply.cgi. The manipulation of the argument Channel/ApCliSsid leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-05-31)
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-05-03: 2Mentions · 2026-05-15: 1Mentions · 2026-05-31: 3Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-31: 305-0305-1505-31
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-032
Disclosure1General1
2026-05-151
Patch1
2026-05-313
Disclosure3
Full discourse6 posts
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Shenzhen Libituo Technology LBT-T300-HW1 (CVE-2026-7675) https://vuldb.com/vuln/360828

    Post summary

    The notice announces the disclosure of a severe vulnerability (CVE-2026-7675) affecting the Shenzhen Libituo LBT-T300-HW1 device.

    0101095
    2.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Shenzhen Libituo Technology's LBT-T300-HW1 network device ships with two unauthenticated remote buffer overflow vulnerabilities (CVE-2026-7674, CVE-2026-7675, both CVSS 8.8), disclosed May 3, 2026. The vendor has not responded. No patch is available. Remote attackers need…

    Post summary

    Shenzhen Libituo's LBT‑T300‑HW1 device has two unauthenticated remote buffer overflows (CVE‑2026‑7674/7675, CVSS 8.8) disclosed on May 3, 2026; the vendor has not responded and no patch is yet available.

    1000046
    236 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-7674 and CVE-2026-7675 follow identical exploitation patterns: an unauthenticated attacker can manipulate specific arguments (vpnpptpserver and vpnl2tpserver) in the startsingleservice() function, sending malformed data that overflows the allocated buffer. The…

    Post summary

    The passage details two CVEs that enable unauthenticated attackers to trigger a buffer overflow by manipulating specific arguments, although no PoC, exploit code, or patch information is provided.

    1000034
    236 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Device That Never Got Patched: Shenzhen Libituo''s Dual CVSS 8.8 Buffer Overflow Crisis. Shenzhen Libituo Technology's LBT-T300-HW1 network device ships with two unauthenticated remote buffer overflow vulnerabilities CVE-2026-7674, CVE-2026-7675, both CVSS 8.8,…

    Post summary

    New unauthenticated remote buffer overflow vulnerabilities (CVE-2026-7674/7675) with CVSS 8.8 have been disclosed for Shenzhen Libituo's LBT‑T300‑HW1 device, which remains unpatched.

    1000042
    236 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    A high-severity buffer overflow vulnerability (CVE-2026-7675) affects Shenzhen Libituo LBT-T300-HW1 devices. This flaw can be exploited remotely. Mohawk Valley SMBs and healthcare orgs should review device security and seek patches or mitigations promptly. #Cybersecurity

    Post summary

    The post announces a high‑severity buffer overflow flaw in Shenzhen Libituo LBT‑T300‑HW1 devices and urges stakeholders to apply available patches or mitigations promptly.

    0000050
    80 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7675 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7675 #CVE-2026-7675 #CVE #High #CyberSecurity #InfoSec https://t.co/I9B3PcPEmx

    Post summary

    The tweet merely announces a new high‑severity CVE, linking to the NVD, without providing exploitation details, patches, or technical specifics.

    0000056
    151 followersView on X

Explore more