EXPOSURES › CVE-2010-5330
CVE-2010-5330
HIGH ⌖ ON CISA KEV · EXPLOITEDUbiquiti AirOS devices suffered a command injection flaw via stainfo.cgi that was actively exploited in the wild.
An unpatched command injection vulnerability in Ubiquiti AirOS allowed attackers to execute arbitrary commands on network devices, leading to potential full device compromise. DIB organizations must ensure all network hardware is patched and monitored for active exploitation, as this flaw was long known and remained unaddressed despite being in the KEV catalog.
Shame score — The vendor failed to patch a known, actively exploited vulnerability for years, demonstrating severe negligence and leaving critical network infrastructure vulnerable to remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.