Executive brief
A security vulnerability exists in the UGREEN CM933 device's administrative interface. This flaw allows an unauthorized person on the same local network to bypass security checks and access management functions without a password. This could lead to unauthorized configuration changes or disruption of the device's operations.
Technical details
A missing authentication vulnerability (CWE-306/CWE-287) exists in the administrative interface of UGREEN CM933 version 1.1.59.4319. The flaw is located within an unknown function of the management component, where insufficient validation allows for authentication bypass. An attacker located on the same local network (adjacent) can exploit this without any prior credentials or user interaction. Successful exploitation grants the attacker access to administrative functions, potentially allowing for unauthorized device configuration or information disclosure. The vendor has acknowledged the issue and scheduled a fix for late April 2026.
Affected products
- UGREEN CM933 1.1.59.4319
Timeline
- 2026-05-09: disclosed
- 2026-05-09: advisory
- 2026-04-30: patched: Vendor scheduled fix for late April 2026