← Back

CVE-2015-9266

nvd nist
Published: Sep 5, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.

Affected (12)

9 products
Airmax Ac Firmware
Airmax M Xm Firmware
Airmax M Xw Firmware
Airmax M Ti Firmware
Airgateway Firmware
Airfiber Af24 Firmware
Airfiber Af24hd Firmware
Af5x Firmware
Af5 Firmware
3 products
Airos 4 Xs2
Airos 4 Xs5
Edgeswitch Xp Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.1.3
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 5.6.2
Running on/withPlatform Versions
Ui
Airmax M Xm
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 5.6.2
Running on/withPlatform Versions
Ui
Airmax M Xw
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 5.6.2
Running on/withPlatform Versions
Ui
Airmax M Ti
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.15
Running on/withPlatform Versions
Ui
Airgateway
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.2.1
Running on/withPlatform Versions
Ui
Airfiber Af24
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.2.1
Running on/withPlatform Versions
Ui
Airfiber Af24hd
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.0.2.1
Running on/withPlatform Versions
Ui
Af5x
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.2.1
Running on/withPlatform Versions
Ui
Af5
All versions
Configuration J
2 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 4.0.4
Before 4.0.4
Running on/withPlatform Versions
Ui
Airmax Ac
All versions
Ui
Airmax M
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.3.2
Running on/withPlatform Versions
Ui
Edgeswitch Xp
All versions

References (14)

Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.