← back
CVE-2026-35081highCWE-20

Arbitrary process termination vulnerability in method ugw-logstop

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.2epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in the ugw-logstop method lets someone with basic user access stop any running process on the system by sending improper input. This could crash important services and disrupt how the system works.

Technical detail

The ugw-logstop method fails to validate user-supplied input before terminating processes, allowing an authenticated attacker to abuse the functionality to kill arbitrary processes. This requires user-level privileges and can result in denial of service or system instability by terminating critical services.

Summary generated and translated by AI from the official description.
The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N