← All CVEs

CVE-2015-9266

critical · 9.8

The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.

9.8
CVSS
74.0%
EPSS (exploit prob.)
99th
EPSS percentile
2018-09-05
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
uiairmax_ac_firmware7.1.3
uiairmax_acall versions
uiairmax_m_xm_firmware< 5.6.2
uiairmax_m_xmall versions
uiairmax_m_xw_firmware< 5.6.2
uiairmax_m_xwall versions
uiairmax_m_ti_firmware< 5.6.2
uiairmax_m_tiall versions
uiairgateway_firmware< 1.15
uiairgatewayall versions
uiairfiber_af24_firmware< 2.2.1
uiairfiber_af24all versions
uiairfiber_af24hd_firmware< 2.2.1
uiairfiber_af24hdall versions
uiaf5x_firmware< 3.0.2.1
uiaf5xall versions
uiaf5_firmware< 2.2.1
uiaf5all versions
ubntairos_4_xs2< 4.0.4
ubntairos_4_xs5< 4.0.4
uiairmax_acall versions
uiairmax_mall versions
ubntedgeswitch_xp_firmware< 1.3.2
uiedgeswitch_xpall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-9266