Description
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.
Published: 2018-09-05
Score: 9.8 Critical
EPSS: 79.0% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Ubnt Airos 4 Xs2 Airos 4 Xs5 Edgeswitch Xp Firmware
Ui Af5 Af5 Firmware Af5x Af5x Firmware Airfiber Af24 Airfiber Af24 Firmware Airfiber Af24hd Airfiber Af24hd Firmware Airgateway Airgateway Firmware Airmax Ac Airmax Ac Firmware Airmax M Airmax M Ti Airmax M Ti Firmware Airmax M Xm Airmax M Xm Firmware Airmax M Xw Airmax M Xw Firmware Edgeswitch Xp
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T08:43:42.375Z

Reserved: 2018-09-04T00:00:00.000Z

Link: CVE-2015-9266

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-09-05T20:29:00.253

Modified: 2024-11-21T02:40:12.417

Link: CVE-2015-9266

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses