PT-2021-11103 · Ucopia · Ucopia Wi-Fi Appliances
Published
2021-02-02
·
Updated
2021-02-04
·
CVE-2020-25036
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
UCOPIA Wi-Fi appliances version 6.0.5
Description:
The issue allows authenticated remote attackers to escape the restricted administration shell CLI and access a shell with admin user rights via an unprotected
less command.Recommendations:
For UCOPIA Wi-Fi appliances version 6.0.5, consider restricting access to the
less command as a temporary workaround until a patch is available.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ucopia Wi-Fi Appliances