ZDI-23-107: (Pwn2Own) Ubiquiti Networks EdgeOS dhcp6c Command Injection Remote Code Execution Vulnerability
Published Feb 9, 2023
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Ubiquiti Networks EdgeOS. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Ubiquiti Networks EdgeOS
Event History
Feb 9, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-107?
The severity of ZDI-23-107 is critical due to the potential for arbitrary code execution without authentication.
2
How do I fix ZDI-23-107?
To mitigate ZDI-23-107, update Ubiquiti Networks EdgeOS to the latest patched version provided by the vendor.
3
Who is affected by ZDI-23-107?
ZDI-23-107 affects installations of Ubiquiti Networks EdgeOS that are accessible to network-adjacent attackers.
4
What type of attack is ZDI-23-107 related to?
ZDI-23-107 is related to remote code execution attacks that can be executed without authentication.
5
Is authentication required to exploit ZDI-23-107?
No, authentication is not required to exploit ZDI-23-107, making it more dangerous.