CVE Explorer
CVE-2026-26048
The Wi-Fi router is vulnerable to de-authentication attacks due to the
absence of management frame protection, allowing forged deauthentication
and disassociation frames to be broadcast without authentication or
encryption. An attacker can use this to cause unauthorized disruptions
and create a denial-of-service condition.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"USR-W610","vendor":"Jinan USR IOT Technology Limited (PUSR)","versions":[{"lessThanOrEqual":"3.1.1.0","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6faddc11195220ce661a609ca830eb6900c5da68b226220e02600e7dbc0bb319 · sha256:27506ee7c32f7190… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6faddc11195220ce661a609ca830eb6900c5da68b226220e02600e7dbc0bb319 · sha256:27506ee7c32f7190… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-306","description":"CWE-306","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6faddc11195220ce661a609ca830eb6900c5da68b226220e02600e7dbc0bb319 · sha256:27506ee7c32f7190… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-050-03.json"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6faddc11195220ce661a609ca830eb6900c5da68b226220e02600e7dbc0bb319 · sha256:27506ee7c32f7190… · /containers/cna/references/1
{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-050-03"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6faddc11195220ce661a609ca830eb6900c5da68b226220e02600e7dbc0bb319 · sha256:27506ee7c32f7190… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.