UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with root privileges using chroothole_client’s PHP call, a related issue to CVE-2017-11322.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25035
Reference (s):
- https://blog.globadis.com/blog/ucopia-v6-multiple-cves-root/
- https://ucopia.com/en/solutions/product-line-wifi/