Executive brief
The UZ801 4G LTE router contains a security flaw that allows anyone connected to its Wi-Fi or local network to take full control of the device. This occurs because a diagnostic tool used by developers was left active and unprotected. An attacker can use this to steal data, monitor internet traffic, or disable the router entirely.
Technical details
A critical incorrect access control vulnerability exists in the UZ801_v2.1 4G LTE Router due to the exposure of the Android Debug Bridge daemon (adbd) on a non-standard port (TCP 7628). The service is accessible over the adjacent network (LAN/Wi-Fi) and does not require any authentication or authorization. An attacker can connect using a standard ADB client to gain an interactive root shell. This allows for full system compromise, including arbitrary code execution, credential theft, and persistent device manipulation.
Affected products
- Generic OEM UZ801_v2.1 4G LTE Router V3.4.3
Timeline
- 2026-07-17: disclosed: Initial disclosure via GitHub and NVD assignment.
- 2026-07-17: advisory