ZDI-24-881: (Pwn2Own) Ubiquiti Networks EV Station setDebugPortEnabled Exposed Dangerous Method Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Ubiquiti Networks EV Station. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2024-29206.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-881?
ZDI-24-881 has been assigned a critical severity rating due to the potential for arbitrary code execution.
How do I fix ZDI-24-881?
To fix ZDI-24-881, you should apply the latest security patch provided by Ubiquiti Networks for the EV Station.
Who is affected by ZDI-24-881?
ZDI-24-881 affects installations of Ubiquiti Networks EV Station that are exposed to network-adjacent attackers.
Can authentication protect against ZDI-24-881?
Although authentication is typically required, the vulnerability in ZDI-24-881 allows attackers to bypass the existing authentication mechanism.
What type of attacks can ZDI-24-881 enable?
ZDI-24-881 can enable network-adjacent attackers to execute arbitrary code on vulnerable systems.