CVE-2020-3936: Unisoon Ultralog Express Firmware
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.
Affected products
- Unisoon Ultralog Express Firmware: version 1.4.0 only
Published 2020-03-27. Last modified 2026-06-17.