Record summary

CVE-2019-3495 has a selected CVSS score of 8.8 (high).

Description

An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload, allowing an attacker to upload .php files and execute code on the server with root user privileges. Authentication for accessing this component can be bypassed by using Hard coded credentials.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 21, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

References

4