CVE-2023-2377: Ubiquiti EdgeRouter X Web Management command injection
A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The impacted element is an unknown function of the component Web Management Interface. The manipulation of the argument Name results in command injection. The attack can be launched remotely. The exploit is now public and may be used. There is ongoing doubt regarding the real existence of this vulnerability. The vendor position is that post-authentication issues are not accepted as vulnerabilities.
Other sources
A vulnerability was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Web Management Interface. The manipulation of the argument name leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227653 was assigned to this vulnerability.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2377?
The severity of CVE-2023-2377 is high with a severity value of 8.8.
What component is affected by CVE-2023-2377?
The Web Management Interface component is affected by CVE-2023-2377.
How can CVE-2023-2377 be exploited?
CVE-2023-2377 can be exploited through command injection by manipulating the argument name.
Which versions of Ubiquiti EdgeRouter X are affected by CVE-2023-2377?
Ubiquiti EdgeRouter X up to version 2.0.9-hotfix.6 are affected by CVE-2023-2377.
How can I fix CVE-2023-2377?
Update your Ubiquiti EdgeRouter X firmware to a version higher than 2.0.9-hotfix.6 to fix CVE-2023-2377.