CVE-2015-9266

The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ui:airmax_ac_firmware:7.1.3:*:*:*:*:*:*:*
cpe:2.3:h:ui:airmax_ac:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ui:airmax_m_xm_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airmax_m_xm:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ui:airmax_m_xw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airmax_m_xw:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ui:airmax_m_ti_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airmax_m_ti:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ui:airgateway_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airgateway:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ui:airfiber_af24_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airfiber_af24:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:ui:airfiber_af24hd_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airfiber_af24hd:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:ui:af5x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:af5x:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:ui:af5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:af5:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
OR cpe:2.3:o:ubnt:airos_4_xs2:*:*:*:*:*:*:*:*
cpe:2.3:o:ubnt:airos_4_xs5:*:*:*:*:*:*:*:*
OR cpe:2.3:h:ui:airmax_ac:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:airmax_m:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:ubnt:edgeswitch_xp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:edgeswitch_xp:-:*:*:*:*:*:*:*

History

12 Aug 2021, 16:43

Type Values Removed Values Added
CPE cpe:2.3:h:ubnt:airgateway:-:*:*:*:*:*:*:*
cpe:2.3:o:ubnt:airmax_m_ti_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ubnt:airmax_m:-:*:*:*:*:*:*:*
cpe:2.3:h:ubnt:airmax_m_xm:-:*:*:*:*:*:*:*
cpe:2.3:o:ubnt:af5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ubnt:af5:-:*:*:*:*:*:*:*
cpe:2.3:o:ubnt:airmax_m_xm_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ubnt:airmax_m_ti:-:*:*:*:*:*:*:*
cpe:2.3:h:ubnt:airfiber_af24:-:*:*:*:*:*:*:*
cpe:2.3:h:ubnt:af5x:-:*:*:*:*:*:*:*
cpe:2.3:o:ubnt:airgateway_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ubnt:airfiber_af24hd:-:*:*:*:*:*:*:*
cpe:2.3:h:ubnt:airmax_ac:-:*:*:*:*:*:*:*
cpe:2.3:o:ubnt:airfiber_af24_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ubnt:airmax_ac_firmware:7.1.3:*:*:*:*:*:*:*
cpe:2.3:o:ubnt:af5x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ubnt:airmax_m_xw:-:*:*:*:*:*:*:*
cpe:2.3:o:ubnt:airmax_m_xw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ubnt:airfiber_af24hd_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ubnt:edgeswitch_xp:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:airfiber_af24:-:*:*:*:*:*:*:*
cpe:2.3:o:ui:af5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ui:airmax_m_xw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airmax_m:-:*:*:*:*:*:*:*
cpe:2.3:o:ui:airgateway_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ui:airmax_ac_firmware:7.1.3:*:*:*:*:*:*:*
cpe:2.3:h:ui:af5:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:airgateway:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:airmax_ac:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:airmax_m_xm:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:edgeswitch_xp:-:*:*:*:*:*:*:*
cpe:2.3:o:ui:airfiber_af24_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:af5x:-:*:*:*:*:*:*:*
cpe:2.3:o:ui:airmax_m_xm_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airmax_m_xw:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:airfiber_af24hd:-:*:*:*:*:*:*:*
cpe:2.3:o:ui:af5x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ui:airmax_m_ti_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ui:airmax_m_ti:-:*:*:*:*:*:*:*
cpe:2.3:o:ui:airfiber_af24hd_firmware:*:*:*:*:*:*:*:*

Information

Published : 2018-09-05 20:29

Updated : 2023-12-10 12:44


NVD link : CVE-2015-9266

Mitre link : CVE-2015-9266

CVE.ORG link : CVE-2015-9266


JSON object : View

Products Affected

ui

  • airmax_m_xw_firmware
  • airmax_m_xm_firmware
  • af5_firmware
  • af5x
  • airfiber_af24hd
  • af5x_firmware
  • airfiber_af24hd_firmware
  • airfiber_af24
  • airgateway_firmware
  • airfiber_af24_firmware
  • airmax_ac_firmware
  • airmax_m_xm
  • airmax_m_xw
  • airmax_m_ti
  • airmax_m_ti_firmware
  • af5
  • airgateway
  • edgeswitch_xp
  • airmax_m
  • airmax_ac

ubnt

  • edgeswitch_xp_firmware
  • airos_4_xs2
  • airos_4_xs5
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')