PT-2023-3998 · Ubiquiti · Aircube+1

Published

2023-05-01

·

Updated

2024-10-29

·

CVE-2023-31998

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Ubiquiti EdgeRouter versions prior to 2.0.9-hotfix.7 Ubiquiti AirCube versions prior to 2.8.9
Description A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices. The issue is related to the MiniUPnPd service in these devices, which can be exploited by an attacker on the local network to potentially execute arbitrary code. Although there are no signs of this vulnerability being used in real-world attacks, users are recommended to update their devices as soon as possible.
Recommendations For Ubiquiti EdgeRouter versions prior to 2.0.9-hotfix.7, update to version 2.0.9-hotfix.7 or later. For Ubiquiti AirCube versions prior to 2.8.9, update to version 2.8.9 or later. As a temporary workaround, consider disabling the MiniUPnPd service until a patch is available. Restrict access to the UPnP service to minimize the risk of exploitation.

Fix

Memory Corruption

Heap Based Buffer Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-04296
CVE-2023-31998

Affected Products

Aircube
Edgerouter X