PT-2021-11103 · Ucopia · Ucopia Wi-Fi Appliances

Published

2021-02-02

·

Updated

2021-02-04

·

CVE-2020-25036

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: UCOPIA Wi-Fi appliances version 6.0.5
Description: The issue allows authenticated remote attackers to escape the restricted administration shell CLI and access a shell with admin user rights via an unprotected less command.
Recommendations: For UCOPIA Wi-Fi appliances version 6.0.5, consider restricting access to the less command as a temporary workaround until a patch is available.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25036

Affected Products

Ucopia Wi-Fi Appliances