Product
An unauthenticated command injection vulnerability in a modified uhttpd server allows remote code execution with root privileges via crafted HTTP Basic Authentication headers.