CVE-2015-9266
Last modified
CVE-2015-9266 is a vulnerability of currently unknown severity. The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. EPSS estimates a 74.00% chance of exploitation in the next 30 days.
Description
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ui | Airmax Ac Firmware | 7.1.3 |
| Ui | Airmax M Xm Firmware | < 5.6.2 |
| Ui | Airmax M Xw Firmware | < 5.6.2 |
| Ui | Airmax M Ti Firmware | < 5.6.2 |
| Ui | Airgateway Firmware | < 1.15 |
| Ui | Airfiber Af24 Firmware | < 2.2.1 |
| Ui | Airfiber Af24hd Firmware | < 2.2.1 |
| Ui | Af5x Firmware | < 3.0.2.1 |
| Ui | Af5 Firmware | < 2.2.1 |
| Ubnt | Airos 4 Xs2 | < 4.0.4 |
| Ubnt | Airos 4 Xs5 | < 4.0.4 |
| Ubnt | Edgeswitch Xp Firmware | < 1.3.2 |
References
- https://hackerone.com/reports/73480Issue Tracking, Third Party Advisory
- https://www.exploit-db.com/exploits/39701/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39853/Exploit, Third Party Advisory, VDB Entry
- https://www.rapid7.com/db/modules/exploit/linux/ssh/ubiquiti_airos_file_uploadExploit, Third Party Advisory
- https://hackerone.com/reports/73480Issue Tracking, Third Party Advisory
- https://www.exploit-db.com/exploits/39701/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39853/Exploit, Third Party Advisory, VDB Entry
- https://www.rapid7.com/db/modules/exploit/linux/ssh/ubiquiti_airos_file_uploadExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-9266?
How severe is CVE-2015-9266?
How do I fix CVE-2015-9266?
Are you affected by CVE-2015-9266?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
