Ubiquiti Administration Portal CSRF / Remote Command Execution

Discussion in 'News Aggregator' started by Packet Storm, 29 Jun 2016.

  1. Packet Storm

    Packet Storm Guest

    The Ubiquiti AirGateway, AirFiber, and mFi platforms feature remote administration via an authenticated web-based portal. Lack of CSRF protection in the Remote Administration Portal, and unsafe passing of user input to operating system commands executed with root privileges, can be abused in a way that enables remote command execution.

    Continue reading...
     

Share This Page

Loading...