← Back to browse · API

CVE-2015-9266

Severity
CRITICAL
CVSS
9.8
EPSS
0.73999
Risk score
65.1
CISA KEV
No
PoC
No
Published
2018-09-05
Modified
2024-08-06
First seen
2026-08-07
Aliases
EUVD-2015-9108, GHSA-8GJ2-CPJJ-73RF
Products
n/a:n/a n/a
Sources
euvd EUVD-2015-9108

Description

The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.

References