CVE-2015-9266
Last modified
CVE-2015-9266 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. EPSS estimates a 74.00% chance of exploitation in the next 30 days.
Description
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.
Metrics
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ui | Airmax Ac Firmware | 7.1.3 |
| Ui | Airmax M Xm Firmware | < 5.6.2 |
| Ui | Airmax M Xw Firmware | < 5.6.2 |
| Ui | Airmax M Ti Firmware | < 5.6.2 |
| Ui | Airgateway Firmware | < 1.15 |
| Ui | Airfiber Af24 Firmware | < 2.2.1 |
| Ui | Airfiber Af24hd Firmware | < 2.2.1 |
| Ui | Af5x Firmware | < 3.0.2.1 |
| Ui | Af5 Firmware | < 2.2.1 |
| Ubnt | Airos 4 Xs2 | < 4.0.4 |
| Ubnt | Airos 4 Xs5 | < 4.0.4 |
| Ubnt | Edgeswitch Xp Firmware | < 1.3.2 |
References
- https://hackerone.com/reports/73480Issue Tracking, Third Party Advisory
- https://www.exploit-db.com/exploits/39701/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39853/Exploit, Third Party Advisory, VDB Entry
- https://www.rapid7.com/db/modules/exploit/linux/ssh/ubiquiti_airos_file_uploadExploit, Third Party Advisory
- https://hackerone.com/reports/73480Issue Tracking, Third Party Advisory
- https://www.exploit-db.com/exploits/39701/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39853/Exploit, Third Party Advisory, VDB Entry
- https://www.rapid7.com/db/modules/exploit/linux/ssh/ubiquiti_airos_file_uploadExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-9266?
How severe is CVE-2015-9266?
How do I fix CVE-2015-9266?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-9260An issue was discovered in BEdita before 3.7.0. A cross-site…5.4
- CVE-2015-9261huft_build in archival/libarchive/decompress_gunzip.c in Bus…5.5
- CVE-2015-9262_XcursorThemeInherits in library.c in libXcursor before 1.1.…
- CVE-2015-9263An issue was discovered in post2file.php in Up.Time Monitori…
- CVE-2015-9264Lansweeper 4.x through 6.x before 6.0.0.48 allows attackers …
- CVE-2015-9265Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2015-9267Nullsoft Scriptable Install System (NSIS) before 2.49 uses t…5.5
- CVE-2015-9268Nullsoft Scriptable Install System (NSIS) before 2.49 has un…7.8
- CVE-2015-9269The export/content.php exportarticle feature in the wordpres…
- CVE-2015-9270XSS exists in the the-holiday-calendar plugin before 1.11.3 …
- CVE-2015-9271The VideoWhisper videowhisper-video-conference-integration p…
- CVE-2015-9272The videowhisper-video-presentation plugin 3.31.17 for WordP…
Are you affected by CVE-2015-9266?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
