CVE-2022-43553: High severity ubiquiti edgerouter firmware vulnerability
A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with an operator account to run arbitrary administrator commands.This vulnerability is fixed in Version 2.0.9-hotfix.5 and later.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43553?
The severity of CVE-2022-43553 is high with a severity value of 8.8.
Which versions of EdgeRouters are affected by CVE-2022-43553?
EdgeRouters Version 2.0.9-hotfix.4 and earlier are affected by CVE-2022-43553.
How can I fix CVE-2022-43553?
To fix CVE-2022-43553, upgrade to EdgeRouters Version 2.0.9-hotfix.5 or later.
What can a malicious actor do with CVE-2022-43553?
With CVE-2022-43553, a malicious actor with an operator account can run arbitrary administrator commands.
Where can I find more information about CVE-2022-43553?
More information about CVE-2022-43553 can be found in the following reference: <a href='https://community.ui.com/releases/Security-Advisory-Bulletin-026-026/07697c65-30b3-4c06-a158-35e06534480d'>https://community.ui.com/releases/Security-Advisory-Bulletin-026-026/07697c65-30b3-4c06-a158-35e06534480d</a>