External risk intelligence

UZ801_v2.1 4G LTE Router Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-52199

The vulnerability affects a 4G LTE router, which is a network edge device typically deployed as an internet gateway. These devices are designed to be public-facing to manage network connectivity, often exposing administrative or service components directly to the internet in common deployment patterns.

Code Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An important vulnerability has been identified in a 4G LTE router that could allow a remote attacker to execute arbitrary code. This type of device often serves as a critical network gateway, making any security weakness a potential concern for ensuring operational continuity and data integrity. The main concern is confirming relevance and exposure of this technology within our environment.

  • Code execution flaw in network gateway.
  • Affects external-facing network edge devices.
  • Confirm if this router type is deployed.

Attack Path

How an attacker could exploit the issue

An attacker can reach the vulnerable component of a 4G LTE router over the network. By interacting with the sbin/adbd component, the attacker can trigger the vulnerability. Successful exploitation could allow an attacker to execute arbitrary code on the device.

  • No special access needed to reach.
  • Triggers via the sbin/adbd component.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A critical vulnerability in the 4G LTE router's `sbin/adbd` component could allow a remote attacker to execute arbitrary code. This could occur when the router's administrative or service components are exposed to the internet, potentially impacting the router's functionality and the network it manages.

  • Router code execution and network access.
  • Remote attackers exploit exposed services.
  • Compromised router, potential network disruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in a 4G LTE router's `adbd` component likely falls under the responsibility of the infrastructure or network operations team, who manage edge devices. Vendor management may also be involved if the router is a purchased service. The immediate priority is to locate all instances of this router, determine their exposure to the internet, and assess their business criticality to prioritize remediation efforts.

  • Ownership: Infrastructure and network operations teams.
  • Verify: Internet exposure and business criticality.
  • Action: Plan risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the UZ801_v2.1 4G LTE Router?

The UZ801_v2.1 is a network gateway device designed to manage 4G LTE cellular connectivity. It acts as a bridge between local network traffic and the internet, commonly used in remote locations or branch offices to provide reliable internet access to connected devices.

What does CVE-2026-52199 mean for the router's security?

This vulnerability involves improper control of generation of code or command injection, classified as CWE-77 and CWE-94. Essentially, the router fails to properly sanitize input before processing it. This allows an unauthorized user to force the device to run unintended commands, effectively taking control of the system.

How is the vulnerability in sbin/adbd triggered?

An attacker triggers this flaw by sending specifically crafted network requests to the sbin/adbd component on the router. This does not require any prior authentication or special user privileges. However, it is only triggered if the attacker can reach this specific service over the network; local traffic restricted from accessing service ports would not trigger the issue.

Why should I care about CVE-2026-52199?

According to Halo Surface Signal, this vulnerability is highly relevant because 4G LTE routers are typically internet-facing edge devices. Because they are designed to be public-facing to maintain connectivity, the vulnerable service is often directly reachable from the internet, making it a prime target for remote interference.

What are the first steps to address this CVE?

Your priority is to identify every UZ801_v2.1 router within your infrastructure. Once located, check if these devices are exposed to the internet or if they can be restricted to internal-only management. Work with your network operations team to assess how critical these devices are to your daily business and plan for updates or configuration changes.

References