CVE-2023-1458: Command Injection
DISPUTED A vulnerability has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6 and classified as critical. Affected by this vulnerability is an unknown functionality of the component OSPF Handler. The manipulation of the argument area leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The associated identifier of this vulnerability is VDB-223303. NOTE: The vendor position is that post-authentication issues are not accepted as vulnerabilities.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1458?
The severity of CVE-2023-1458 is critical with a CVSS score of 9.8.
What is the affected software of CVE-2023-1458?
The affected software of CVE-2023-1458 is Ubiquiti EdgeRouter X 2.0.9-hotfix.6.
What is the vulnerability description of CVE-2023-1458?
CVE-2023-1458 is a critical vulnerability in Ubiquiti EdgeRouter X 2.0.9-hotfix.6 that allows command injection through manipulation of the argument area in the OSPF Handler component.
Is CVE-2023-1458 currently being attacked remotely?
There are reports of remote attacks targeting CVE-2023-1458.
How can I fix CVE-2023-1458?
To fix CVE-2023-1458, it is recommended to update Ubiquiti EdgeRouter X firmware to version 2.0.9-hotfix7 or later.