Command Injection Vulnerability in UniSoC Vowifi Service
CVE-2025-31715

9.8CRITICAL

What is CVE-2025-31715?

A command injection vulnerability exists in the Vowifi service provided by UniSoC, resulting from inadequate input validation. This flaw allows an attacker to execute arbitrary commands, potentially leading to remote privilege escalation without the need for additional execution privileges. Organizations using affected versions of the Vowifi service should implement security measures to mitigate this risk.

Affected Version(s)

SL8521E/SL8521ET/ SL8541E/UIS8141E/UWS6137/UWS6137E/UWS6151(E)/UWS6152 Mocor5/Andorid8.1/Andorid9

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-31715 : Command Injection Vulnerability in UniSoC Vowifi Service