peter bassill · operator
$ cve CVE-2023-34635 JSON

CVE-2023-34635 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 3.5% (pctl 89)

Patch early

A public exploit exists.

Description

Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.54% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2023-07-31
Last modified2026-06-17

Affected (1)

VendorProduct
wifi-softunibox administration

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD