CVE-2026-52199
9.1Generic OEM · UZ801_v2.1 4G LTE Router
A critical vulnerability in the UZ801_v2.1 4G LTE Router allows remote, unauthenticated attackers to execute arbitrary code via the sbin/adbd component.
Executive summary
A critical remote code execution vulnerability in Generic OEM UZ801 4G LTE routers poses a significant risk to network integrity and confidentiality.
Vulnerability
The flaw exists within the sbin/adbd component, which fails to properly validate requests. An unauthenticated remote attacker can leverage this weakness to achieve arbitrary code execution on the device.
Business impact
The ability for an unauthenticated attacker to execute arbitrary code on a network routing device represents a critical security failure. Successful exploitation could lead to full system compromise, allowing attackers to intercept network traffic, pivot into internal segments, or establish persistent backdoors, resulting in severe data loss and operational disruption. The high CVSS score of 9.1 reflects the ease of exploitation over a network without requiring authentication.
Remediation
Immediate Action: Since a vendor patch is currently unavailable, administrators should immediately restrict access to the device management interface by placing it behind a firewall or VPN, and disable remote access features if they are not strictly required for business operations.
Proactive Monitoring: Monitor device logs for anomalous entries related to the sbin/adbd process and audit network traffic for unexpected command and control patterns originating from the router.
Compensating Controls: Deploy strict egress and ingress filtering to prevent unauthorized external connections to the router management interface, and utilize a Web Application Firewall or similar inspection tool to detect malicious payloads targeting the device.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the linked research repository.
Analyst recommendation
Given the critical nature of this vulnerability and the existence of a public proof-of-concept, organizations using the affected Generic OEM hardware must treat this as a high priority. Until a firmware update is released, the device must be isolated from the public internet to prevent potential remote exploitation. Security teams should prioritize replacing or decommissioning these units if vendor support and patching are not forthcoming.