Impact
A remote attacker can leverage a flaw in the sbin/adbd component of the Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 to inject arbitrary command sequences, leading to full code execution on the device. The vulnerability is a classic command injection (CWE‑77) combined with code injection (CWE‑94) that enables the attacker to execute any system command. Attackers could compromise confidentiality, integrity, and availability of the router’s administrative functions and potentially egress to the connected network.
Affected Systems
The affected product is Generic OEM UZ801_v2.1 4G LTE Router, firmware version V3.4.3. No other vendors or products are listed, so the scope is limited to this specific device and firmware build.
Risk and Exploitability
The CVSS score of 9.1 reflects a high severity, with remote reachability and full privileges granted upon exploitation. The EPSS score of less than 1% indicates that exploitation is currently rare. The CVE is not listed in the CISA KEV catalog. Attackers would need network access to the router’s adbd or management interface; the module’s command injection supports arbitrary code execution, making the risk high if an attacker can reach it.
OpenCVE Enrichment