Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2023-31998

Disclosure Date: July 18, 2023 (last updated February 25, 2025)
A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices.
Attacker Value
Unknown

CVE-2023-2373

Disclosure Date: April 28, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown part of the component Web Management Interface. The manipulation of the argument ecn-up leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227649 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-43553

Disclosure Date: December 05, 2022 (last updated February 24, 2025)
A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with an operator account to run arbitrary administrator commands.This vulnerability is fixed in Version 2.0.9-hotfix.5 and later.
Attacker Value
Unknown

CVE-2021-22909

Disclosure Date: May 27, 2021 (last updated February 22, 2025)
A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-middle (MitM) attack during a firmware update. This vulnerability is fixed in EdgeMAX EdgeRouter V2.0.9-hotfix.1 and later.
Attacker Value
Unknown

CVE-2020-8282

Disclosure Date: December 14, 2020 (last updated February 22, 2025)
A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have been able to perform unauthorized remote code execution.
Attacker Value
Unknown

CVE-2020-8234

Disclosure Date: August 21, 2020 (last updated February 22, 2025)
A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be guessed, enabling the attacker to obtain high privileges and get a root shell by a Command injection.
Attacker Value
Unknown

CVE-2017-0938

Disclosure Date: February 12, 2019 (last updated November 27, 2024)
Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attacks.