ZDI-CAN-23318: ZDI-24-881: (Pwn2Own) Ubiquiti Networks EV Station setDebugPortEnabled Exposed Dangerous Method Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Ubiquiti Networks EV Station. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2024-29206.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23318?
The severity of ZDI-CAN-23318 is high due to the potential for arbitrary code execution.
How do I fix ZDI-CAN-23318?
You can fix ZDI-CAN-23318 by applying the latest security patches provided by Ubiquiti Networks for the EV Station.
Who is affected by ZDI-CAN-23318?
ZDI-CAN-23318 affects installations of Ubiquiti Networks EV Station that have not been secured against this vulnerability.
What types of attacks can exploit ZDI-CAN-23318?
ZDI-CAN-23318 can be exploited by network-adjacent attackers to execute arbitrary code.
Is authentication needed to exploit ZDI-CAN-23318?
Yes, but the existing authentication mechanism can be bypassed, making the vulnerability critical.