CVE-2025-6102
Last modified
CVE-2025-6102 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnerability is an unknown functionality of the file /authentication/logout.php. EPSS estimates a 2.78% chance of exploitation in the next 30 days.
Description
A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnerability is an unknown functionality of the file /authentication/logout.php. The manipulation of the argument mac_address leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-6102?
How severe is CVE-2025-6102?
How do I fix CVE-2025-6102?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-6099A vulnerability was found in szluyu99 gin-vue-blog up to 61d…5.5
- CVE-2025-60991A reflected cross-site scripted (XSS) vulnerability in Codaz…8.8
- CVE-2025-6100A vulnerability was found in realguoshuai open-video-cms 1.0…6.3
- CVE-2025-6101A vulnerability classified as critical has been found in let…5.5
- CVE-2025-61018An issue in the sqlo_place_dt_set component of openlink virt…7.5
- CVE-2025-61019An issue in the sqlo_key_part_best component of openlink vir…7.5
- CVE-2025-61020An issue in the sqlo_strip_in_join component of openlink vir…7.5
- CVE-2025-61021An issue in the sqlo_natural_join_cond component of openlink…7.5
- CVE-2025-61022An issue in the sqlo_tb_col_preds component of openlink virt…7.5
- CVE-2025-61023An issue in the st_compare component of openlink virtuoso-op…7.5
- CVE-2025-61024An issue in the sqlo_try_in_loop component of openlink virtu…7.5
- CVE-2025-61025An issue in the sslr_qst_get component of openlink virtuoso-…7.5
Are you affected by CVE-2025-6102?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
