An adversary can read any log file on the system by manipulating the logfile parameter in the ubr-logread method in wwwubr.cgi.

CWE: CWE-20:Improper Input Validation