Junglewise Threat Intelligence

CVE-2010-5330: Ubiquiti AirOS Command Injection Vulnerability

CVE-2010-5330 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-04-15

Vendors: Ubiquiti.

Executive brief

A command injection vulnerability exists in Ubiquiti AirOS devices via the 'ifname' variable in GET requests to stainfo.cgi. Lack of proper sanitization for shell metacharacters allows unauthenticated remote attackers to execute arbitrary commands on the device.

Affected products

  • Ubiquiti AirOS (802.11 ISP products) < 4.0.1
  • Ubiquiti AirOS (AirMax ISP products) < 5.3.5
  • Ubiquiti AirOS (AirSync firmware) < 5.4.5
  • Ubiquiti Nanostation5

Timeline

  • 2010-06-30: disclosed: Exploit-DB entry 14146 published
  • 2019-06-11: disclosed: NVD Published Date
  • 2022-04-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-15: exploited: Reported as exploited in the wild by CISA