First published: Mon May 01 2017(Updated: )
Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability. An attacker with access to an operator (read-only) account could lure an admin (root) user to access the attacker-controlled page, allowing the attacker to gain admin privileges in the system.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ubnt Edgeos | <=1.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0933 is a Cross-Site Request Forgery (CSRF) vulnerability in Ubiquiti Networks EdgeOS version 1.9.1 and prior.
The severity of CVE-2017-0933 is high with a severity value of 8.
An attacker with access to an operator (read-only) account could trick an admin (root) user to access a page controlled by the attacker, allowing them to gain admin privileges in the system.
To fix CVE-2017-0933, update Ubiquiti Networks EdgeOS to version 1.9.1.1 or later, as mentioned in the [Ubiquiti Networks EdgeMAX Updates Blog](https://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMAX-EdgeRouter-software-release-v1-9-1-1/ba-p/1910524).
Yes, you can find more details about CVE-2017-0933 in the [HackerOne report](https://hackerone.com/reports/240098).