CVE-2023-34635 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 3.5% (pctl 89)
Patch early
A public exploit exists.
Description
Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.54% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2023-07-31 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| wifi-soft | unibox administration |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Wifi Soft Unibox Administration 3.0 & 3.1 - SQL Injection | 2023-07-20 |
References
→ the Explorer · watch your stack · NVD