Loading HuntDB...

Command injection in the process of downloading the latest version of the cloud key firmware through the unifi management software.

High
U
Ubiquiti Inc.
Submitted None

Team Summary

Official summary from Ubiquiti Inc.

In UniFi Cloud Key versions prior to `5.3.12`, `5.4.9` and `5.5.2`, the firmware is downloaded in a unprotected channel, with allow an attacker in an MitM scenario to interfere with the communication, and possibly modifying the firmware during an update. The versions `5.3.12`, `5.4.9` and `5.5.2` fix this problem by utilizing encrypted channel to download the firmware.

Reported by dblack

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Command Injection - Generic