Ubiquiti.Networks.AirOS.admin.cgi.Remote.Command.Execution
Description
This indicates an attack attempt to exploit a Remote Command Execution vulnerability in Ubiquiti Networks AirOS.
The vulnerability is due to insufficient sanitizing of user supplied inputs in "admin.cgi" script of the application. As a result, a remote attacker may be able to execute arbitrary command within the context of the application, by sending a crafted HTTP request to the server.
Affected Products
Ubiquiti Networks, Inc. AirOS 3.6.1
Ubiquiti Networks, Inc. AirOS 4.0
Ubiquiti Networks, Inc. AirOS 5
Impact
System Compromise: Remote attackers can gain control of vulnerable systems
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
http://www.ubnt.com/support/downloads
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |