CVE-2019-3495
Description
Arbitrary file upload in Wifi-soft UniBox controller allows unauthenticated attackers to execute code as root via hardcoded credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Arbitrary file upload in Wifi-soft UniBox controller allows unauthenticated attackers to execute code as root via hardcoded credentials.
Vulnerability
An arbitrary file upload vulnerability exists in the network/mesh/edit-nds.php endpoint of Wifi-soft UniBox controller versions 0.x through 2.x. The endpoint does not properly validate uploaded files, allowing an attacker to upload .php files. Authentication for this component can be bypassed using hardcoded credentials, as disclosed in [1].
Exploitation
An attacker can first bypass authentication by leveraging the hardcoded credentials (e.g., default username/password) to access the administrative interface. Once authenticated, the attacker uploads a malicious .php file via network/mesh/edit-nds.php. The file is then executed on the server.
Impact
Successful exploitation results in remote code execution with root user privileges, leading to full compromise of the UniBox controller. The attacker can execute arbitrary commands, install malware, or pivot to other network resources.
Mitigation
No official patch has been released for this vulnerability. Affected users should restrict network access to the UniBox controller, disable the vulnerable endpoint if possible, and change any default credentials. Consider isolating the device on a segmented network until a fix is available.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: 0.x through 2.x
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- packetstormsecurity.com/files/151077/Wifi-soft-Unibox-2.x-Remote-Command-Code-Injection.htmlmitrex_refsource_MISC
- seclists.org/fulldisclosure/2019/Jan/23mitremailing-listx_refsource_MLIST
- sahildhar.github.io/blogpost/Multiple-RCE-Vulnerabilties-in-Unibox-Controller-0.x-3.x/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.