SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2010-5330

Ubiquiti AirOS Command Injection Vulnerability

KEVCRITICAL 9.8EPSS 33.8%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 6 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
33.85% probability · 98th percentile
CISA KEV
Listed 15 April 2022 · due 6 May 2022
Weakness
CWE-77
Affected
ui/airos
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2010-5330

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.