Skip to content
COOEY

EXPOSURES › CVE-2010-5330

CVE-2010-5330

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-15 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2010-5330 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Ubiquiti AirOS devices suffered a command injection flaw via stainfo.cgi that was actively exploited in the wild.

An unpatched command injection vulnerability in Ubiquiti AirOS allowed attackers to execute arbitrary commands on network devices, leading to potential full device compromise. DIB organizations must ensure all network hardware is patched and monitored for active exploitation, as this flaw was long known and remained unaddressed despite being in the KEV catalog.

Shame score — The vendor failed to patch a known, actively exploited vulnerability for years, demonstrating severe negligence and leaving critical network infrastructure vulnerable to remote code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.