Description
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component
Published: 2026-07-17
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A remote attacker can leverage a flaw in the sbin/adbd component of the Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 to inject arbitrary command sequences, leading to full code execution on the device. The vulnerability is a classic command injection (CWE‑77) combined with code injection (CWE‑94) that enables the attacker to execute any system command. Attackers could compromise confidentiality, integrity, and availability of the router’s administrative functions and potentially egress to the connected network.

Affected Systems

The affected product is Generic OEM UZ801_v2.1 4G LTE Router, firmware version V3.4.3. No other vendors or products are listed, so the scope is limited to this specific device and firmware build.

Risk and Exploitability

The CVSS score of 9.1 reflects a high severity, with remote reachability and full privileges granted upon exploitation. The EPSS score of less than 1% indicates that exploitation is currently rare. The CVE is not listed in the CISA KEV catalog. Attackers would need network access to the router’s adbd or management interface; the module’s command injection supports arbitrary code execution, making the risk high if an attacker can reach it.

Generated by OpenCVE AI on August 1, 2026 at 08:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or block the sbin/adbd service or its listening ports using systemd or firewall rules.
  • Restrict access to the router’s management interfaces to trusted IPs only, applying firewall or network segmentation.
  • Apply a vendor‑released firmware update or patch that fixes this vulnerability; if none is available, contact the vendor for a remediation plan.

Generated by OpenCVE AI on August 1, 2026 at 08:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sat, 01 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via adbd Command Injection on Generic OEM UZ801

Tue, 28 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via adbd Command Injection on Generic OEM UZ801

Sun, 26 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Adbd in Generic OEM UZ801 Router

Wed, 22 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Adbd in Generic OEM UZ801 Router

Mon, 20 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
CWE-94
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-20T17:59:28.219Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52199

cve-icon Vulnrichment

Updated: 2026-07-20T17:59:22.529Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T08:45:02Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')