CVE-2010-5330: Ubiquiti AirOS
EPSS39.3%No. 945 of 1739 in KEV
CVE year2010~12 yrs before listing
Same vendor in KEV4
Same product1
| Field | Value |
|---|---|
| Vendor | Ubiquiti |
| Product | AirOS |
| Name | Ubiquiti AirOS Command Injection Vulnerability |
| Added to KEV | 2022-04-15 |
| US federal due date | 2022-05-06 |
| Ransomware use | Unknown |
| CWE | CWE-77 |
CISA description
Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Ubiquiti AirOS vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-15.