Ucopia develops wireless appliances and captive-portal controllers that manage network access and authentication across small-to-medium enterprise deployments. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the exposure recurs through OS command injection, improper authentication, and insecure file-upload flaws that are characteristic of internet-facing network appliances with administrative interfaces. Defenders should treat disclosed firmware updates for this vendor's wireless appliance line as priority patches and restrict management-interface exposure; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ucopia over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-11322HIGH The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileges via a dollar sign ($) metacharacter in the argument to ch | Oct 3, 2017 | 8.2 | 31 | NO | YES |
CVE-2017-11321HIGH The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admin' privileges via shell metacharacters in the less command. | Oct 3, 2017 | 7.2 | 31 | NO | YES |
CVE-2022-44720CRITICAL An issue was discovered in Weblib Ucopia before 6.0.13. OS Command Injection injection can occur, related to chroot. | Jun 29, 2023 | 9.8 | 30 | NO | NO |
CVE-2018-15481HIGH Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices using firmware version 5.1.x before 5.1.13 allows authenticated remote a | Aug 21, 2018 | 8.8 | 28 | NO | NO |
CVE-2020-25036HIGH UCOPIA Wi-Fi appliances 6.0.5 allow authenticated remote attackers to escape the restricted administration shell CLI, and access a shell with admin user rights, via an unprotected | Feb 2, 2021 | 8.8 | 26 | NO | NO |
CVE-2022-44719HIGH An issue was discovered in Weblib Ucopia before 6.0.13. The SSH Server has Insecure Permissions. | Jun 29, 2023 | 7.5 | 24 | NO | NO |
CVE-2020-25037HIGH UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with admin user privileges via an escape from a restricted command. | Feb 2, 2021 | 8.2 | 24 | NO | NO |
CVE-2017-17743MEDIUM Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.20, 5.0.x before 5.0.19, and 5.1.x before 5.1.11 allows authe | Mar 22, 2018 | 6.7 | 21 | NO | NO |
CVE-2020-25035MEDIUM UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with root privileges using chroothole_client's PHP call, a related issue to CVE-2017-11322. | Feb 2, 2021 | 6.7 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ucopia.
Media articles that mention a CVE ID that affects a product developed by Ucopia — matched by CVE ID, not by vendor name.