Vulnerability Description
Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remote attackers to execute arbitrary code with admin credentials, because /opt/vyatta/share/vyatta-cfg/templates/system/static-host-mapping/host-name/node.def does not sanitize the 'alias' or 'ips' parameter for shell metacharacters.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ui | Edgeos | 1.9.1 |
| Ui | Erlite-3 | - |
Related Weaknesses (CWE)
References
- https://www.red4sec.com/cve/edgerouter_lite.txtExploitThird Party Advisory
- https://www.red4sec.com/cve/edgerouter_lite.txtExploitThird Party Advisory
FAQ
What is CVE-2018-5265?
CVE-2018-5265 is a vulnerability with a CVSS score of 7.2 (HIGH). Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remote attackers to execute arbitrary code with admin credentials, because /opt/vyatta/share/vyatta-cfg/templates/system/static-host-mapping/hos...
How severe is CVE-2018-5265?
CVE-2018-5265 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5265?
Check the references section above for vendor advisories and patch information. Affected products include: Ui Edgeos, Ui Erlite-3.