peter bassill · operator
$ cve CVE-2015-9266 JSON

CVE-2015-9266 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 74% (pctl 99)

Patch early

A public exploit exists.

Description

The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS74% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2018-09-05
Last modified2026-06-17

Affected (23)

VendorProduct
ubntairos 4 xs2
ubntairos 4 xs5
ubntedgeswitch xp firmware
uiaf5
uiaf5 firmware
uiaf5x
uiaf5x firmware
uiairfiber af24
uiairfiber af24 firmware
uiairfiber af24hd
uiairfiber af24hd firmware
uiairgateway
uiairgateway firmware
uiairmax ac
uiairmax ac firmware
uiairmax m
uiairmax m ti
uiairmax m ti firmware
uiairmax m xm
uiairmax m xm firmware
uiairmax m xw
uiairmax m xw firmware
uiedgeswitch xp

Public exploits

SourceTitleDate
exploit-dbAirOS 6.x - Arbitrary File Upload2016-04-15

References

→ the Explorer  ·  watch your stack  ·  NVD