ZDI-CAN-23186: ZDI-24-879: (Pwn2Own) Ubiquiti Networks EV Station changeUserPassword Missing Authentication Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Ubiquiti Networks EV Station. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-29208.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23186?
ZDI-CAN-23186 has been assigned a CVSS rating of 8.8, indicating a high severity level.
How do I fix ZDI-CAN-23186?
To fix ZDI-CAN-23186, ensure to apply the latest firmware updates provided by Ubiquiti Networks for the EV Station.
What types of attacks can ZDI-CAN-23186 enable?
ZDI-CAN-23186 allows network-adjacent attackers to execute arbitrary code on affected installations of the Ubiquiti Networks EV Station.
Is authentication required to exploit ZDI-CAN-23186?
No, authentication is not required to exploit the ZDI-CAN-23186 vulnerability.
Which product is affected by ZDI-CAN-23186?
The affected product is the Ubiquiti Networks EV Station.