Back to CVE List

CVE-2026-39880

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
5.0 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

Vulnerability Description

Remnawave Backend is the backend for the Remnawave proxy and user management solution. Prior to 2.7.5, a glitch in the HWID device registration logic allows an authenticated user to bypass the configured limit for HWID devices and register more devices than expected, allowing them to resell subscriptions and consume excessive traffic. This vulnerability is fixed in 2.7.5.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-362
Source
NVD
Vendor
remnawave
Product
backend

External References

Discussion (0)

Add Comment

No comments yet. Be the first!