First published: Mon Dec 05 2022(Updated: )
A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with an operator account to run arbitrary administrator commands.This vulnerability is fixed in Version 2.0.9-hotfix.5 and later.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ui Edgemax Edgerouter Firmware | <2.0.9 | |
Ui Edgemax Edgerouter Firmware | =2.0.9 | |
Ui Edgemax Edgerouter Firmware | =2.0.9-hotfix1 | |
Ui Edgemax Edgerouter Firmware | =2.0.9-hotfix2 | |
Ui Edgemax Edgerouter Firmware | =2.0.9-hotfix4 | |
Ui Edgemax Edgerouter | ||
All of | ||
Any of | ||
Ui Edgemax Edgerouter Firmware | <2.0.9 | |
Ui Edgemax Edgerouter Firmware | =2.0.9 | |
Ui Edgemax Edgerouter Firmware | =2.0.9-hotfix1 | |
Ui Edgemax Edgerouter Firmware | =2.0.9-hotfix2 | |
Ui Edgemax Edgerouter Firmware | =2.0.9-hotfix4 | |
Ui Edgemax Edgerouter |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-43553 is high with a severity value of 8.8.
EdgeRouters Version 2.0.9-hotfix.4 and earlier are affected by CVE-2022-43553.
To fix CVE-2022-43553, upgrade to EdgeRouters Version 2.0.9-hotfix.5 or later.
With CVE-2022-43553, a malicious actor with an operator account can run arbitrary administrator commands.
More information about CVE-2022-43553 can be found in the following reference: <a href='https://community.ui.com/releases/Security-Advisory-Bulletin-026-026/07697c65-30b3-4c06-a158-35e06534480d'>https://community.ui.com/releases/Security-Advisory-Bulletin-026-026/07697c65-30b3-4c06-a158-35e06534480d</a>