Impact
The vulnerability exists in the MifiService.apk component of the Generic OEM UZ801_v2.1 firmware V3.4.3 and is a code injection flaw in an AJAX web management API endpoint. By sending crafted requests to the /ajax endpoint, an attacker can inject and execute arbitrary code on the device, effectively gaining full control over the router. This flaw is classified as CWE‑94, indicating that user supplied input is executed without sufficient validation. Based on the description, it is inferred that the endpoint accepts user supplied data that is directly executed, allowing code injection.
Affected Systems
The affected hardware and firmware combination is the Generic OEM UZ801_v2.1 4G LTE Router running firmware V3.4.3. No other vendors or product versions are noted in the CVE data.
Risk and Exploitability
The CVSS score of 9.8 signals that exploitation would provide an attacker with complete system compromise. The EPSS score of < 1% indicates that exploitation attempts are currently rare, although no guarantees exist that no proof‑of‑concept or exploit has been released. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote HTTP request to the router’s /ajax endpoint, which may be exposed over the local or wide‑area network if not properly restricted, allowing an unauthenticated attacker to send malicious payloads.
OpenCVE Enrichment