CVE-2023-2378: Ubiquiti EdgeRouter X Web Management command injection
A flaw has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown function of the component Web Management Interface. This manipulation of the argument suffix-rate-up causes command injection. The attack may be initiated remotely. The exploit has been published and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor position is that post-authentication issues are not accepted as vulnerabilities.
Other sources
A vulnerability was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. It has been rated as critical. Affected by this issue is some unknown functionality of the component Web Management Interface. The manipulation of the argument suffix-rate-up leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227654 is the identifier assigned to this vulnerability.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ubiquiti EdgeRouter Xto a version that resolves this vulnerability.Fixed in 2.0.9-hotfix.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch VDB-227654 - Compensating control
If possible, restrict network access to the EdgeRouter X Web Management Interface so the vulnerable command injection path cannot be reached remotely (e.g., limit management access to trusted IPs via firewall/ACL).
Event History
Frequently Asked Questions
What is the title of CVE-2023-2378?
The title of CVE-2023-2378 is Ubiquiti EdgeRouter X Web Management Interface command injection.
What is the severity of CVE-2023-2378?
The severity of CVE-2023-2378 is rated as high (8.8).
What is affected by CVE-2023-2378?
The Web Management Interface component of Ubiquiti EdgeRouter X up to version 2.0.9-hotfix.6 is affected by CVE-2023-2378.
How can CVE-2023-2378 be exploited?
CVE-2023-2378 can be exploited through command injection by manipulating the argument suffix-rate-up.
Are there any known fixes for CVE-2023-2378?
No specific fix information is provided for CVE-2023-2378. It is recommended to apply the latest updates from the vendor.