UcopiaCVEs & Vulnerabilities

9 CVEs affecting Ucopia products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

wireless appliance 5wireless appliance firmware 4ucopia wireless appliance 3express wireless appliance 1
CVE-2022-44720CRITICAL

An issue was discovered in Weblib Ucopia before 6.0.13. OS Command Injection injection can occur, related to chroot.

29 Jun 2023
9.8
CVSS
CVE-2022-44719HIGH

An issue was discovered in Weblib Ucopia before 6.0.13. The SSH Server has Insecure Permissions.

29 Jun 2023
7.5
CVSS
CVE-2020-25036HIGH

UCOPIA Wi-Fi appliances 6.0.5 allow authenticated remote attackers to escape the restricted administration shell CLI, and access a shell with admin user rights, via an unprotected less command.

2 Feb 2021
8.8
CVSS
CVE-2020-25035MEDIUM

UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with root privileges using chroothole_client's PHP call, a related issue to CVE-2017-11322.

2 Feb 2021
6.7
CVSS
CVE-2020-25037HIGH

UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with admin user privileges via an escape from a restricted command.

2 Feb 2021
8.2
CVSS
CVE-2018-15481HIGH

Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices using firmware version 5.1.x before 5.1.13 allows authenticated remote attackers to escape the shell and escalate their privileges by adding a LocalCommand to the SSH configuration file in the user home folder.

21 Aug 2018
8.8
CVSS
CVE-2017-17743MEDIUM

Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.20, 5.0.x before 5.0.19, and 5.1.x before 5.1.11 allows authenticated remote attackers to escape the shell and escalate their privileges by uploading a .bashrc file containing the /bin/sh string. In some situations, authentication can be achieved via the bhu85tgb default password for the admin account.

22 Mar 2018
6.7
CVSS
CVE-2017-11322HIGHpoc

The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileges via a dollar sign ($) metacharacter in the argument to chroothole_client.

3 Oct 2017
8.2
CVSS
CVE-2017-11321HIGHpoc

The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admin' privileges via shell metacharacters in the less command.

3 Oct 2017
7.2
CVSS
← PrevPage 1 / 1Next →
Ucopia CVEs & Vulnerabilities — 9 Tracked