Junglewise Threat Intelligence

CVE-2026-52200: Generic OEM UZ801 4G LTE Router remote code execution in /ajax API

CVE-2026-52200 · Severity: info · CVSS 9.8 · Published 2026-07-08

Executive brief

A critical security vulnerability has been identified in the Generic OEM UZ801 4G LTE router, a device used to provide mobile internet connectivity. An attacker can remotely take full control of the device by sending malicious requests to its web management interface. This could lead to the theft of sensitive data, interception of internet traffic, or the device being used as a foothold to attack other systems on the local network.

Technical details

A remote code execution (RCE) vulnerability exists in the Generic OEM UZ801_v2.1 4G LTE Router running firmware version V3.4.3. The flaw is located within the /ajax web management API endpoint, which is handled by the MifiService.apk component. Due to improper input validation or broken access control in this API, a remote, unauthenticated attacker can send specially crafted requests to execute arbitrary system commands. This allows for complete compromise of the device's operating system. No user interaction is required for exploitation.

Affected products

  • Generic OEM UZ801_v2.1 4G LTE Router V3.4.3

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory

References

Related threats