Indionetworks develops the Unibox product line, a family of unified communication and collaboration appliances that serve as critical infrastructure for enterprise deployments. The observed vulnerability pattern centers on configuration and input-handling weaknesses characteristic of embedded administrative interfaces: hard-coded credentials, cross-site request forgery, OS command injection, and unrestricted file uploads that create pathways to authentication bypass and remote code execution. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Indionetworks over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3497HIGH An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. The tools/ping Ping feature of the Diagnostic Tools component is vulnerable to Remote Command Execut | Mar 21, 2019 | 8.8 | 32 | NO | NO |
CVE-2019-3496HIGH An issue was discovered on Wifi-soft UniBox controller 3.x devices. The tools/controller/diagnostic_tools_controller Diagnostic Tools Controller is vulnerable to Remote Command Exe | Mar 21, 2019 | 8.8 | 30 | NO | NO |
CVE-2020-21883HIGH Unibox U-50 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a OS command injection vulnerability in /tools/ping, which can leads to complete device takeov | Apr 9, 2021 | 8.8 | 29 | NO | NO |
CVE-2020-21884HIGH Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/network-trace, /list_users, /list_b | Apr 9, 2021 | 8.8 | 24 | NO | NO |
CVE-2019-3495HIGH An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload, allowing an attacker to upload .ph | Mar 21, 2019 | 8.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Indionetworks.
Media articles that mention a CVE ID that affects a product developed by Indionetworks — matched by CVE ID, not by vendor name.