CVE-2026-26048
Jinan USR IOT Technology Limited (PUSR) USR-W610 Missing Authentication for Critical Function
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
20 Feb 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Wi-Fi router is vulnerable to de-authentication attacks due to the
absence of management frame protection, allowing forged deauthentication
and disassociation frames to be broadcast without authentication or
encryption. An attacker can use this to cause unauthorized disruptions
and create a denial-of-service condition.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Jinan USR IOT Technology Limited (PUSR) · USR-W610Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →