Ubiquiti Administration Portal CSRF / Remote Command Execution
Posted by deepcore on June 30, 2016 – 12:56 am
The Ubiquiti AirGateway, AirFiber, and mFi platforms feature remote administration via an authenticated web-based portal. Lack of CSRF protection in the Remote Administration Portal, and unsafe passing of user input to operating system commands executed with root privileges, can be abused in a way that enables remote command execution.
Post a reply
You must be logged in to post a comment.