ZDI-CAN-19687: ZDI-23-107: (Pwn2Own) Ubiquiti Networks EdgeOS dhcp6c Command Injection Remote Code Execution Vulnerability
Published Feb 9, 2023
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Ubiquiti Networks EdgeOS. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Ubiquiti Networks EdgeOS
Event History
Feb 9, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-19687?
ZDI-CAN-19687 is considered a critical vulnerability due to its ability to allow arbitrary code execution without authentication.
2
How do I fix ZDI-CAN-19687?
To fix ZDI-CAN-19687, update your Ubiquiti Networks EdgeOS to the latest patched version provided by the vendor.
3
Who is affected by ZDI-CAN-19687?
All installations of Ubiquiti Networks EdgeOS are potentially affected by ZDI-CAN-19687.
4
What type of attacks can ZDI-CAN-19687 enable?
ZDI-CAN-19687 enables network-adjacent attackers to execute arbitrary code on vulnerable systems.
5
Is authentication required to exploit ZDI-CAN-19687?
No, authentication is not required to exploit ZDI-CAN-19687, making it more dangerous.