References https://nvd.nist.gov/vuln/detail/CVE-2025-6104 https://github.com/advisories/GHSA-q46m-9r94-rhrw https://www.cvedetails.com/cve/CVE-2025-6104/ https://github.com/h0e4a0r1t/h0e4a0r1t.github.io/blob/master/2025/1/Command%20Injection%20Vulnerability%20in%20Wifi-soft%20UniBox%20controller-billing-pms_check.pdf https://cert.kenet.or.ke/cve-2025-6104-wifi-soft-unibox-controller-os-command-injection-vulnerability https://www.ameeba.com/blog/cve-2025-6104-critical-os-command-injection-vulnerability-in-wifi-soft-unibox-controller/ https://cve.imfht.com/detail/CVE-2025-6104?lang=en https://vulners.com/cve/CVE-2025-6104 https://www.cvelogic.com/cve/CVE-2025-6104
Related VulnerabilitiesWifi-soft UniBox Controller /authentication/test_userlogin.php 命令执行漏洞Wifi-soft UniBox /authentication/logout.php 命令执行漏洞 (CVE-2025-6102)PoCunibox-router-fileread: Unibox路由器任意文件读取漏洞PoCunibox-router-update-byod-sqli: Unibox路由器update_byod.php-SQL注入漏洞Wifi-soft UniBox /billing/pms_check.php 命令执行漏洞 (CVE-2025-6104)Unibox update_byod.php SQL注入漏洞unibox路由器 update_byod.php sql注入Wifi-soft UniBox controller /tools/download_csv.php 文件读取漏洞unibox路由器存在任意文件读取漏洞Unibox路由器 /authentication/logout 存在远程命令执行漏洞