CVE-2024-54749: High severity ubiquiti u7-pro vulnerability
Ubiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: this is disputed by the Supplier because the observation only established that a password is present in a firmware image; however, the device cannot be deployed without setting a new password during installation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54749?
CVE-2024-54749 is considered to have a high severity due to the presence of a hardcoded password that allows attackers to gain root access.
How do I fix CVE-2024-54749?
To address CVE-2024-54749, it is recommended to update the firmware of the Ubiquiti U7-Pro to a version that resolves this vulnerability.
What devices are affected by CVE-2024-54749?
CVE-2024-54749 specifically affects the Ubiquiti U7-Pro device running version 7.0.35.
Can CVE-2024-54749 lead to full system compromise?
Yes, CVE-2024-54749 can potentially lead to full system compromise by allowing unauthorized access as root.
Is CVE-2024-54749 under dispute by the vendor?
Yes, the vendor disputes the findings of CVE-2024-54749, claiming that the observation does not confirm exploitable access.