ubnt records
6 published records for vendor ubnt.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 16.7%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-269 Improper Privilege Management2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2015-9266Weaponized | Ubiquiti airOS HTTP(S) unauthenticated arbitrary file uploadui · airmax ac firmware · CWE-22 | Critical9.8 | — | 74.0% | Sep 5, 2018 |
35Monitor | CVE-2017-0934No exploit | Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection ofubnt · edgeos · CWE-269 | High8.8 | — | 1.3% | Mar 22, 2018 |
35Monitor | CVE-2017-0932No exploit | Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of validation ubnt · edgeos · CWE-269 | High8.8 | — | 1.2% | Mar 22, 2018 |
32Monitor | CVE-2017-0933No exploit | Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability.ubnt · edgeos · CWE-352 | High8.0 | — | 0.5% | Mar 22, 2018 |
29Monitor | CVE-2018-12591No exploit | Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an improperly neutralized element in an OS command due to lack of protectioubnt · edgeswitch firmware · CWE-78 | High7.2 | — | 1.9% | Jun 20, 2018 |
18Monitor | CVE-2017-0913No exploit | Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system.ubnt · ucrm · CWE-732 | Medium4.7 | — | 0.3% | Jul 3, 2018 |
- CVE-2015-926661This week
Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload
CriticalCVSS 9.8WeaponizedEPSS 74%ui · airmax ac firmwareSep 5, 2018
- CVE-2017-093435Monitor
Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of
HighCVSS 8.8No exploitEPSS 1%ubnt · edgeosMar 22, 2018
- CVE-2017-093235Monitor
Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of validation
HighCVSS 8.8No exploitEPSS 1%ubnt · edgeosMar 22, 2018
- CVE-2017-093332Monitor
Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability.
HighCVSS 8.0No exploitEPSS 1%ubnt · edgeosMar 22, 2018
- CVE-2018-1259129Monitor
Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an improperly neutralized element in an OS command due to lack of protectio
HighCVSS 7.2No exploitEPSS 2%ubnt · edgeswitch firmwareJun 20, 2018
- CVE-2017-091318Monitor
Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system.
MediumCVSS 4.7No exploitEPSS 0%ubnt · ucrmJul 3, 2018