CVE-2023-31998: High severity ubiquiti edgerouter firmware vulnerability
Published Jul 18, 2023
·Updated
A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices.
Affected Software
8 affected components
UI Edgemax Edgerouter Firmware=2.0.9
UI Edgemax Edgerouter
UI Aircube Firmware<2.8.9
UI Aircube
All of the following
UI Edgemax Edgerouter Firmware=2.0.9
UI Edgemax Edgerouter
All of the following
UI Aircube Firmware<2.8.9
UI Aircube
Remediation
Event History
Jul 18, 2023
CVE Published
via MITRE·01:40 AM
Data Sourced
via MITRE·01:40 AM
DescriptionSeverity
Data Sourced
03:15 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-31998.
2
What is the severity of CVE-2023-31998?
The severity of CVE-2023-31998 is high with a CVSS score of 7.5.
3
Which devices are affected by CVE-2023-31998?
EdgeRouters and Aircubes are affected by CVE-2023-31998.
4
How does CVE-2023-31998 impact the affected devices?
CVE-2023-31998 allows a malicious actor to interrupt UPnP service on EdgeRouters and Aircubes.
5
Is there a fix available for CVE-2023-31998?
There is no available fix for CVE-2023-31998 at the moment. It is recommended to follow the vendor's security advisory for updates.