CVE-2015-9266
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.
Affected (12)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1.3 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.6.2 |
| Running on/with | Platform Versions |
|---|---|
Ui Airmax M Xm | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.6.2 |
| Running on/with | Platform Versions |
|---|---|
Ui Airmax M Xw | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.6.2 |
| Running on/with | Platform Versions |
|---|---|
Ui Airmax M Ti | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.15 |
| Running on/with | Platform Versions |
|---|---|
Ui Airgateway | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.2.1 |
| Running on/with | Platform Versions |
|---|---|
Ui Airfiber Af24 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.2.1 |
| Running on/with | Platform Versions |
|---|---|
Ui Airfiber Af24hd | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.2.1 |
| Running on/with | Platform Versions |
|---|---|
Ui Af5x | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.2.1 |
| Running on/with | Platform Versions |
|---|---|
Ui Af5 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.0.4 | |
| Before 4.0.4 |
| Running on/with | Platform Versions |
|---|---|
Ui Airmax Ac | All versions |
Ui Airmax M | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.3.2 |
| Running on/with | Platform Versions |
|---|---|
Ui Edgeswitch Xp | All versions |
References (14)
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.