CVE-2020-21883: Indionetworks Unibox u1000 Firmware
High severity, CVSS 8.8. EPSS: 4.1% chance of exploitation in the next 30 days.
Unibox U-50 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a OS command injection vulnerability in /tools/ping, which can leads to complete device takeover.
Affected products
- Indionetworks Unibox u1000 Firmware: version 2.4 only
- Indionetworks Unibox u2500 Firmware: version 2.4 only
- Indionetworks Unibox u5000 Firmware: version 2.4 only
- Indionetworks Unibox u500 Firmware: version 2.4 only
- Indionetworks Unibox u50 Firmware: version 2.4 only
Published 2021-04-09. Last modified 2026-07-09.