Loading HuntDB...

Code Execution in restricted CLI of EdgeSwitch

High
U
Ubiquiti Inc.
Submitted None

Team Summary

Official summary from Ubiquiti Inc.

In EdgeSwitch 1.7.3 and prior, an user with admin credentials can make use of specially crafted commands to execute arbitrary shell instructions, bypassing the SSH/TELNET CLI interface.

Reported by maxpl0it

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Command Injection - Generic