Loading HuntDB...

[EdgeSwitch] Web GUI command injection as root with Privilege-1 and Privilege-15 users

Medium
U
Ubiquiti Inc.
Submitted None

Team Summary

Official summary from Ubiquiti Inc.

The researcher found a privilege escalation in the EdgeSwitch prior to version `1.7.1`, an CGI script don't fully sanitize the user input resulting in local commands execution, allowing an operator user (`Privilege-1`) to escalate privileges and became administrator (`Privilege-15`).

Reported by phenix

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Command Injection - Generic