CVE-2015-9266
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 74.0%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 74.00% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- ui/airmax ac firmware · ui/airmax m xm firmware · ui/airmax m xw firmware · ui/airmax m ti firmware · ui/airgateway firmware · ui/airfiber af24 firmware · ui/airfiber af24hd firmware · ui/af5x firmware · ui/af5 firmware · ubnt/airos 4 xs2 · ubnt/airos 4 xs5 · ubnt/edgeswitch xp firmware
- Source
- cve@mitre.org
References
- https://community.ubnt.com/t5/airMAX-General-Discussion/Virus-attack-URGENT-UBNT/td-p/1562940Vendor Advisory
- https://community.ubnt.com/t5/airMAX-Updates-Blog/Important-Security-Notice-and-airOS-5-6-5-Release/ba-p/1565949Vendor Advisory
- https://community.ubnt.com/t5/airMAX-Updates-Blog/Security-Release-for-airMAX-TOUGHSwitch-and-airGateway-Released/ba-p/1300494Patch, Vendor Advisory
- https://hackerone.com/reports/73480Issue Tracking, Third Party Advisory
- https://www.exploit-db.com/exploits/39701/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39853/Exploit, Third Party Advisory, VDB Entry
- https://www.rapid7.com/db/modules/exploit/linux/ssh/ubiquiti_airos_file_uploadExploit, Third Party Advisory
- https://community.ubnt.com/t5/airMAX-General-Discussion/Virus-attack-URGENT-UBNT/td-p/1562940Vendor Advisory
- https://community.ubnt.com/t5/airMAX-Updates-Blog/Important-Security-Notice-and-airOS-5-6-5-Release/ba-p/1565949Vendor Advisory
- https://community.ubnt.com/t5/airMAX-Updates-Blog/Security-Release-for-airMAX-TOUGHSwitch-and-airGateway-Released/ba-p/1300494Patch, Vendor Advisory
- https://hackerone.com/reports/73480Issue Tracking, Third Party Advisory
- https://www.exploit-db.com/exploits/39701/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39853/Exploit, Third Party Advisory, VDB Entry
- https://www.rapid7.com/db/modules/exploit/linux/ssh/ubiquiti_airos_file_uploadExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.