UI
UI Airos: vulnerabilidades y CVE
UI Airos tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas2
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2010-5330 | Crítica (9.8) | 39% | ⚠ Explotación activa | 11 jun 2019 | On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-8171 | Crítica (9.8) | 3.9% | — | 26 may 2020 | We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description… |
| CVE-2020-8170 | Media (6.1) | 1.0% | — | 26 may 2020 | We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description… |
| CVE-2020-8168 | Alta (8.8) | 0.69% | — | 26 may 2020 | We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description… |
| CVE-2010-5330 | Crítica (9.8) | 39% | ⚠ Explotación activa | 11 jun 2019 | On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is… |
| CVE-2017-0938 | Alta (7.5) | 21% | — | 12 feb 2019 | Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attacks. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de UI
Unifi Protect · 21Unifi Network Application · 15Unifi OS · 12Unifi OS Server · 11Unifi Dream Machine PRO Firmware · 11Unifi Dream Machine Special Edition Firmware · 10Unifi Dream Machine PRO MAX Firmware · 10Unifi Dream Router 7 Firmware · 10Enterprise Network Video Recorder Core Firmware · 10Unifi Cloud Gateway Fiber Firmware · 10Unifi Cloud Gateway MAX Firmware · 10Unifi Dream Machine Beast Firmware · 10