CVE-2020-3936: Unisoon Ultralog Express Firmware

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.

Affected products

  • Unisoon Ultralog Express Firmware: version 1.4.0 only

Published 2020-03-27. Last modified 2026-06-17.