CVE-2018-5264
Last modified
CVE-2018-5264 is a vulnerability of currently unknown severity. Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free time" Wi-Fi usage by sending a /guest/s/default/ request to obtain a cookie, and then using this cookie in a /guest/s/default/login request with the byfree parameter.. EPSS estimates a 1.49% chance of exploitation in the next 30 days.
Description
Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free time" Wi-Fi usage by sending a /guest/s/default/ request to obtain a cookie, and then using this cookie in a /guest/s/default/login request with the byfree parameter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ui | Unifi Firmware | All versions |
References
- https://www.red4sec.com/cve/unifi.txtExploit, Third Party Advisory
- https://www.red4sec.com/cve/unifi.txtExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5264?
How severe is CVE-2018-5264?
How do I fix CVE-2018-5264?
Are you affected by CVE-2018-5264?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
