CVE-2020-8168
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:Attackers can abuse multiple end-points not protected against cross-site request forgery (CSRF), as a result authenticated users can be persuaded to visit malicious web pages, which allows attackers to perform arbitrary actions, such as downgrade the device's firmware to older versions, modify configuration, upload arbitrary firmware, exfiltrate files and tokens.Mitigation:Update to the latest AirMax AirOS firmware version available at the AirMax download page.
Published:May 26, 2020
Last Modified:Nov 21, 2024
EPS:May 26, 2020
EPSS Score:0.00315
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Ui
Product
Ag-hp-2g16
Ui
Ag-hp-2g16
Vendor
Ui
Product
Ag-hp-2g20
Ui
Ag-hp-2g20
Vendor
Ui
Product
Ag-hp-5g23
Ui
Ag-hp-5g23
Vendor
Ui
Product
Ag-hp-5g27
Ui
Ag-hp-5g27
Vendor
Ui
Product
Airgrid M
Ui
Airgrid M
Vendor
Ui
Product
Airgrid M2
Ui
Airgrid M2
Vendor
Ui
Product
Airgrid M5
Ui
Airgrid M5
Vendor
Ui
Product
Airos
Ui
Airos
Vendor
Ui
Product
Ar
Ui
Ar
Vendor
Ui
Product
Ar-hp
Ui
Ar-hp
Vendor
Ui
Product
Bm2-ti
Ui
Bm2-ti
Vendor
Ui
Product
Bm2hp
Ui
Bm2hp
Vendor
Ui
Product
Bm5-ti
Ui
Bm5-ti
Vendor
Ui
Product
Bm5hp
Ui
Bm5hp
Vendor
Ui
Product
Is-m5
Ui
Is-m5
Vendor
Ui
Product
Lbem5-23
Ui
Lbem5-23
Vendor
Ui
Product
Litestation M5
Ui
Litestation M5
Vendor
Ui
Product
Locom2
Ui
Locom2
Vendor
Ui
Product
Locom5
Ui
Locom5
Vendor
Ui
Product
Locom9
Ui
Locom9
Vendor
Ui
Product
M2
Ui
M2
Vendor
Ui
Product
M3
Ui
M3
Vendor
Ui
Product
M365
Ui
M365
Vendor
Ui
Product
M5
Ui
M5
Vendor
Ui
Product
M900
Ui
M900
Vendor
Ui
Product
Nb-2g18
Ui
Nb-2g18
Vendor
Ui
Product
Nb-5g22
Ui
Nb-5g22
Vendor
Ui
Product
Nb-5g25
Ui
Nb-5g25
Vendor
Ui
Product
Nbe-m2-13
Ui
Nbe-m2-13
Vendor
Ui
Product
Nbe-m5-16
Ui
Nbe-m5-16
Vendor
Ui
Product
Nbe-m5-19
Ui
Nbe-m5-19
Vendor
Ui
Product
Nbm3
Ui
Nbm3
Vendor
Ui
Product
Nbm365
Ui
Nbm365
Vendor
Ui
Product
Nbm9
Ui
Nbm9
Vendor
Ui
Product
Nsm2
Ui
Nsm2
Vendor
Ui
Product
Nsm3
Ui
Nsm3
Vendor
Ui
Product
Nsm365
Ui
Nsm365
Vendor
Ui
Product
Nsm5
Ui
Nsm5
Vendor
Ui
Product
Pbe-m2-400
Ui
Pbe-m2-400
Vendor
Ui
Product
Pbe-m5-300
Ui
Pbe-m5-300
Vendor
Ui
Product
Pbe-m5-300-iso
Ui
Pbe-m5-300-iso
Vendor
Ui
Product
Pbe-m5-400
Ui
Pbe-m5-400
Vendor
Ui
Product
Pbe-m5-400-iso
Ui
Pbe-m5-400-iso
Vendor
Ui
Product
Pbe-m5-620
Ui
Pbe-m5-620
Vendor
Ui
Product
Pbm10
Ui
Pbm10
Vendor
Ui
Product
Pbm365
Ui
Pbm365
Vendor
Ui
Product
Pbm5
Ui
Pbm5
Vendor
Ui
Product
Picom2hp
Ui
Picom2hp
Vendor
Ui
Product
Power Ap N
Ui
Power Ap N
Vendor
Ui
Product
Rm2-ti
Ui
Rm2-ti
Vendor
Ui
Product
Rm5-ti
Ui
Rm5-ti
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
