Impact
Nginx UI’s self‑upgrade function only compares a downloaded binary against a same‑origin digest obtained from the upgrade mirror. Because the binary itself is not cryptographically signed, a compromised mirror or a network attacker who can alter both the binary and its digest can supply a malicious executable that passes validation. When an administrator initiates an upgrade, the application installs and runs the attacker‑controlled code within the Nginx UI process, potentially at the same privilege level as the UI or Nginx itself. The weakness is a classic unsigned binary download flaw (CWE‑494).
Affected Systems
The vulnerable versions are Nginx UI 2.0.0 through 2.5.0. The issue was fixed in release 2.5.0 and later, which includes proper binary validation. The product is provided by the vendor 0xJacky.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. EPSS is not available, but the absence of a KEV listing does not reduce the risk, because an attacker can still achieve remote code execution by controlling the mirror or performing a MitM attack that delivers matching binaries and digests. Exploitation requires an operator that triggers a self‑upgrade, so the attack surface is limited to environments where administrators voluntarily execute upgrades. Nevertheless, the impact on confidentiality, integrity, and availability is critical when the code runs in the UI process.
OpenCVE Enrichment
Github GHSA