Ubiquiti EdgeRouter X Web Management Interface command injection
CVE-2023-2378
What is CVE-2023-2378?
A command injection vulnerability has been identified in the Web Management Interface of Ubiquiti EdgeRouter X. This issue arises from improper handling of the argument 'suffix-rate-up,' allowing remote attackers to execute arbitrary commands on the device. The vulnerability can be exploited without authentication, making it a significant security concern, especially since the exploit details have been publicly disclosed. Users are urged to update to the latest firmware to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EdgeRouter X 2.0.9-hotfix.0
EdgeRouter X 2.0.9-hotfix.1
EdgeRouter X 2.0.9-hotfix.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
