CVE-2025-6102 | Wifi-soft UniBox Controller up to 20250506 logout.php mac_address os command injection (EUVD-2025-18358)
A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnerability is an unknown functionality of the file /authentication/logout.php. The manipulation of the argument mac_address leads to os command injection.
This vulnerability is known as CVE-2025-6102. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.