An attacker can write to any file on the system through the ubr-editfile method in wwwubr.cgi, which is an unused undocumented API endpoint.

CWE: CWE-912:Hidden Functionality