CVE-2020-25035: Ucopia Express Wireless Appliance

Medium severity, CVSS 6.7. EPSS: 0.5% chance of exploitation in the next 30 days.

UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with root privileges using chroothole_client's PHP call, a related issue to CVE-2017-11322.

Affected products

  • Ucopia Express Wireless Appliance: up to and including 6.0.5

Published 2021-02-02. Last modified 2026-06-17.