PT-2023-19174 · Ubiquiti · Ubiquiti Edgerouter X
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ubiquiti EdgeRouter X versions up to 2.0.9-hotfix.6
Description
A critical issue affects the Web Management Interface component, where the manipulation of the
src argument leads to command injection. This can be initiated remotely.Recommendations
For Ubiquiti EdgeRouter X versions up to 2.0.9-hotfix.6, consider disabling the Web Management Interface until a patch is available to prevent command injection attacks. Restrict access to the interface to minimize the risk of exploitation. Avoid using the
src argument in the affected interface until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ubiquiti Edgerouter X