PT-2020-19997 · Ubiquiti · Airmax Airos
Published
2020-05-26
·
Updated
2020-05-28
·
CVE-2020-8168
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AirMax AirOS versions prior to 6.3.0
Description
The issue allows attackers to abuse multiple endpoints not protected against cross-site request forgery (CSRF). As a result, authenticated users can be persuaded to visit malicious web pages, which enables attackers to perform arbitrary actions. These actions include downgrading the device's firmware to older versions, modifying configuration, uploading arbitrary firmware, exfiltrating files and tokens.
Recommendations
Update to the latest AirMax AirOS firmware version available at the AirMax download page.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Airmax Airos