UGREEN CM933 Missing Authentication Vulnerability in Administrative Interface

Vulnerability

A vulnerability allowing for missing authentication has been identified in the UGREEN CM933 model, specifically in version 1.1.59.4319. The issue arises from an unknown function within the Administrative Interface component, potentially allowing unauthorized access or actions. This vulnerability can only be exploited by someone on the local network.

Impact

Exploitation of this vulnerability could lead to unauthorized access or actions within the Administrative Interface, due to the missing authentication.

Remediation

Users are advised to upgrade to the version scheduled for release in late April, which will address this vulnerability.

Added: May 9, 2026, 11:18 AM
Updated: May 9, 2026, 11:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
4.9
remediation
0.0
relevance
7.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.