CVE-2017-0933: CSRF
Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability. An attacker with access to an operator (read-only) account could lure an admin (root) user to access the attacker-controlled page, allowing the attacker to gain admin privileges in the system.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-0933?
CVE-2017-0933 is a Cross-Site Request Forgery (CSRF) vulnerability in Ubiquiti Networks EdgeOS version 1.9.1 and prior.
What is the severity of CVE-2017-0933?
The severity of CVE-2017-0933 is high with a severity value of 8.
How does CVE-2017-0933 work?
An attacker with access to an operator (read-only) account could trick an admin (root) user to access a page controlled by the attacker, allowing them to gain admin privileges in the system.
How can I fix CVE-2017-0933?
To fix CVE-2017-0933, update Ubiquiti Networks EdgeOS to version 1.9.1.1 or later, as mentioned in the [Ubiquiti Networks EdgeMAX Updates Blog](https://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMAX-EdgeRouter-software-release-v1-9-1-1/ba-p/1910524).
Is there any additional information about CVE-2017-0933?
Yes, you can find more details about CVE-2017-0933 in the [HackerOne report](https://hackerone.com/reports/240098).