packetstormsecurity.com
http://packetstormsecurity.com/files/151077/Wifi-soft-Unibox-2.x-Remote-Command-Code-Injection.html CVE-2019-3495
HIGH
indionetworks unibox_firmware Unrestricted Upload of File with Dangerous Type
Record summary
CVE-2019-3495 has a selected CVSS score of 8.8 (high).
Description
An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload, allowing an attacker to upload .php files and execute code on the server with root user privileges. Authentication for accessing this component can be bypassed by using Hard coded credentials.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 21, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
unibox_firmwareBrowse indionetworks / unibox_firmware | VulnCheck | Version data not supplied | |
References
4[fulldisclosure] 20190106 Multiple Root RCE in Unibox Wifi Access Controller 0.x - 3.xmailing list
http://seclists.org/fulldisclosure/2019/Jan/23 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-3495 sahildhar.github.io
https://sahildhar.github.io/blogpost/Multiple-RCE-Vulnerabilties-in-Unibox-Controller-0.x-3.x