10

CVE-2015-9266

Exploit

Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload

The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ui ≫ Airmax Ac Firmware Version 7.1.3
   Ui ≫ Airmax Ac Version -
Ui ≫ Airmax M Xm Firmware Version < 5.6.2
   Ui ≫ Airmax M Xm Version -
Ui ≫ Airmax M Xw Firmware Version < 5.6.2
   Ui ≫ Airmax M Xw Version -
Ui ≫ Airmax M Ti Firmware Version < 5.6.2
   Ui ≫ Airmax M Ti Version -
Ui ≫ Airgateway Firmware Version < 1.15
   Ui ≫ Airgateway Version -
Ui ≫ Airfiber Af24 Firmware Version < 2.2.1
   Ui ≫ Airfiber Af24 Version -
Ui ≫ Airfiber Af24hd Firmware Version < 2.2.1
   Ui ≫ Airfiber Af24hd Version -
Ui ≫ Af5x Firmware Version < 3.0.2.1
   Ui ≫ Af5x Version -
Ui ≫ Af5 Firmware Version < 2.2.1
   Ui ≫ Af5 Version -
Ubnt ≫ Airos 4 Xs2 Version < 4.0.4
   Ui ≫ Airmax Ac Version -
   Ui ≫ Airmax M Version -
Ubnt ≫ Airos 4 Xs5 Version < 4.0.4
   Ui ≫ Airmax Ac Version -
   Ui ≫ Airmax M Version -
Ubnt ≫ Edgeswitch Xp Firmware Version < 1.3.2
   Ui ≫ Edgeswitch Xp Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 74% 0.994
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
MITRE 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

https://community.ubnt.com/t5/airMAX-General-Discussion/Virus-attack-URGENT-UBNT/td-p/1562940
Vendor Advisory
https://community.ubnt.com/t5/airMAX-Updates-Blog/Important-Security-Notice-and-airOS-5-6-5-Release/ba-p/1565949
Vendor Advisory
https://community.ubnt.com/t5/airMAX-Updates-Blog/Security-Release-for-airMAX-TOUGHSwitch-and-airGateway-Released/ba-p/1300494
Patch
Vendor Advisory
https://hackerone.com/reports/73480
Third Party Advisory
Issue Tracking
https://www.exploit-db.com/exploits/39701/
Third Party Advisory
Exploit
VDB Entry
https://www.exploit-db.com/exploits/39853/
Third Party Advisory
Exploit
VDB Entry
https://www.rapid7.com/db/modules/exploit/linux/ssh/ubiquiti_airos_file_upload
Third Party Advisory
Exploit