CVE-2015-9266
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.
Published:Sep 5, 2018
Last Modified:Nov 21, 2024
EPS:Sep 5, 2018
EPSS Score:0.22956
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Ubnt
Product
Airos 4 Xs2
Ubnt
Airos 4 Xs2
Vendor
Ubnt
Product
Airos 4 Xs5
Ubnt
Airos 4 Xs5
Vendor
Ubnt
Product
Edgeswitch Xp Firmware
Ubnt
Edgeswitch Xp Firmware
Vendor
Ui
Product
Af5
Ui
Af5
Vendor
Ui
Product
Af5 Firmware
Ui
Af5 Firmware
Vendor
Ui
Product
Af5x
Ui
Af5x
Vendor
Ui
Product
Af5x Firmware
Ui
Af5x Firmware
Vendor
Ui
Product
Airfiber Af24
Ui
Airfiber Af24
Vendor
Ui
Product
Airfiber Af24 Firmware
Ui
Airfiber Af24 Firmware
Vendor
Ui
Product
Airfiber Af24hd
Ui
Airfiber Af24hd
Vendor
Ui
Product
Airfiber Af24hd Firmware
Ui
Airfiber Af24hd Firmware
Vendor
Ui
Product
Airgateway
Ui
Airgateway
Vendor
Ui
Product
Airgateway Firmware
Ui
Airgateway Firmware
Vendor
Ui
Product
Airmax Ac
Ui
Airmax Ac
Vendor
Ui
Product
Airmax Ac Firmware
Ui
Airmax Ac Firmware
Vendor
Ui
Product
Airmax M
Ui
Airmax M
Vendor
Ui
Product
Airmax M Ti
Ui
Airmax M Ti
Vendor
Ui
Product
Airmax M Ti Firmware
Ui
Airmax M Ti Firmware
Vendor
Ui
Product
Airmax M Xm
Ui
Airmax M Xm
Vendor
Ui
Product
Airmax M Xm Firmware
Ui
Airmax M Xm Firmware
Vendor
Ui
Product
Airmax M Xw
Ui
Airmax M Xw
Vendor
Ui
Product
Airmax M Xw Firmware
Ui
Airmax M Xw Firmware
Vendor
Ui
Product
Edgeswitch Xp
Ui
Edgeswitch Xp
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
