Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-52200: Arbitrary Code Execution in Generic OEM UZ801 Router
CVE-2026-52200
CVE-2026-52200
Summary
A security issue in the Generic OEM UZ801_v2.1 4G LTE Router's web management API allows a remote attacker to potentially take control of the device. This could happen if the router is not properly secured or if a malicious user gains access to the API. To mitigate this risk, ensure that the router's web management interface is not accessible from the internet and use strong passwords for any users with access to the API.
Original title
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint in MifiService.apk
Original description
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint in MifiService.apk
Vulnerability type
CWE-94
Code Injection
Published: 8 Jul 2026 · Updated: 23 Jul 2026 · First seen: 8 Jul 2026