Home

Description

Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without user interaction. Attackers can craft a malicious webpage that automatically submits a form to change router remote access settings to port 8080 without the user's consent.

PUBLISHED Reserved 2026-01-14 | Published 2026-01-16 | Updated 2026-01-16 | Assigner VulnCheck




MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Problem types

Cross-Site Request Forgery (CSRF)

Product status

EVW327
affected

Credits

lated finder

References

www.exploit-db.com/exploits/49920 (ExploitDB-49920) exploit

www.ubeeinteractive.com (Ubee Interactive Official Homepage) product

www.vulncheck.com/...-access-cross-site-request-forgery-csrf (VulnCheck Advisory: Ubee EVW327 - 'Enable Remote Access' Cross-Site Request Forgery (CSRF)) third-party-advisory

cve.org (CVE-2021-47820)

nvd.nist.gov (CVE-2021-47820)

Download JSON