Vulnerability Description
A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-middle (MitM) attack during a firmware update. This vulnerability is fixed in EdgeMAX EdgeRouter V2.0.9-hotfix.1 and later.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ui | Edgemax Edgerouter Firmware | <= 2.0.9 |
| Ui | Edgemax Edgerouter | - |
Related Weaknesses (CWE)
References
- https://community.ui.com/releases/Security-Advisory-Bulletin-018-018/cfa1566b-4bVendor Advisory
- https://community.ui.com/releases/Security-Advisory-Bulletin-018-018/cfa1566b-4bVendor Advisory
FAQ
What is CVE-2021-22909?
CVE-2021-22909 is a vulnerability with a CVSS score of 7.5 (HIGH). A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-middle (MitM) attack during a firmware update. This vulnerability is fixed in EdgeM...
How severe is CVE-2021-22909?
CVE-2021-22909 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22909?
Check the references section above for vendor advisories and patch information. Affected products include: Ui Edgemax Edgerouter Firmware, Ui Edgemax Edgerouter.