PT-2020-19997 · Ubiquiti · Airmax Airos

Published

2020-05-26

·

Updated

2020-05-28

·

CVE-2020-8168

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AirMax AirOS versions prior to 6.3.0
Description The issue allows attackers to abuse multiple endpoints not protected against cross-site request forgery (CSRF). As a result, authenticated users can be persuaded to visit malicious web pages, which enables attackers to perform arbitrary actions. These actions include downgrading the device's firmware to older versions, modifying configuration, uploading arbitrary firmware, exfiltrating files and tokens.
Recommendations Update to the latest AirMax AirOS firmware version available at the AirMax download page.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8168

Affected Products

Airmax Airos