Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
ssvc Actcvss 9.8epss 39%
from disclosure to weapon
Published on NVDJun 11
CISA KEV+1039d
exploitation probability
39%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-05-06
Apply updates per vendor instructions.
In short
A Ubiquiti device accepts unsanitized user input in a web request, allowing an attacker to run arbitrary system commands on the device. This happens because the device does not properly filter shell commands in a parameter called 'ifname'.
Technical detail
Command Injection vulnerability in stainfo.cgi via unsanitized 'ifname' GET parameter allows unauthenticated remote code execution on affected Ubiquiti devices (Nanostation5, AirMax ISP, AirSync, 802.11 ISP products). The attack vector is a specially crafted HTTP GET request containing shell metacharacters that are executed with device privileges.
Summary generated and translated by AI from the official description.
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected.