Command Injection Vulnerability in Ubiquiti EdgeRouter X
CVE-2023-1457
9.8CRITICAL
What is CVE-2023-1457?
A command injection vulnerability exists in Ubiquiti's EdgeRouter X in the Static Routing Configuration Handler. This vulnerability allows an attacker to manipulate the 'next-hop-interface' argument, potentially enabling remote command execution. While the exploit has been publicly disclosed, the reliability of the vulnerability's existence is currently under scrutiny. The vendor has stated that issues arising post-authentication are typically not categorized as vulnerabilities.
Affected Version(s)
EdgeRouter X 2.0.9-hotfix.6