Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2f2p-6v5f-w6gc

Опубликовано: 28 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS4: 7.3
CVSS3: 6.3

Описание

A vulnerability was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6 and classified as critical. This issue affects some unknown processing of the component Web Management Interface. The manipulation of the argument src leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227651.

A vulnerability was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6 and classified as critical. This issue affects some unknown processing of the component Web Management Interface. The manipulation of the argument src leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227651.

EPSS

Процентиль: 95%
0.09201
Низкий

7.3 High

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-74
CWE-77

Связанные уязвимости

CVSS3: 7.2
nvd
больше 3 лет назад

A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. Impacted is an unknown function of the component Web Management Interface. Executing a manipulation of the argument src can lead to command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The presence of this vulnerability remains uncertain at this time. The vendor position is that post-authentication issues are not accepted as vulnerabilities.

EPSS

Процентиль: 95%
0.09201
Низкий

7.3 High

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-74
CWE-77