{"id":1786,"date":"2017-03-17T10:20:31","date_gmt":"2017-03-17T14:20:31","guid":{"rendered":"https:\/\/solutionsreview.com\/wireless-network\/?p=1786"},"modified":"2017-03-20T15:39:24","modified_gmt":"2017-03-20T19:39:24","slug":"security-flaw-discovered-in-ubiquiti-wireless-gear","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/","title":{"rendered":"Security Flaw Discovered in Ubiquiti Wireless Gear"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"1788\" data-permalink=\"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/ubiquiti-vulnerability\/\" data-orig-file=\"https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability.jpg\" data-orig-size=\"800,350\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Security Flaw Discovered in Ubiquiti Wireless Gear\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability-300x131.jpg\" data-large-file=\"https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability.jpg\" tabindex=\"0\" role=\"button\" class=\"aligncenter wp-image-1788 size-full\" src=\"https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability.jpg\" alt=\"Security Flaw Discovered in Ubiquiti Wireless Gear\" width=\"800\" height=\"350\" srcset=\"https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability.jpg 800w, https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability-300x131.jpg 300w, https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability-768x336.jpg 768w, https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability-600x263.jpg 600w, https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability-617x270.jpg 617w, https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability-180x79.jpg 180w, https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability-400x175.jpg 400w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><strong><span style=\"color: #ff0000\">Note<\/span>: Ubiquiti has since issued a fix for the vulnerability. Find that <a href=\"https:\/\/community.ubnt.com\/t5\/airMAX-General-Discussion\/AirOS-Vulnerability-Issue-Update-3-18-17\/td-p\/1869309\">here.<\/a><\/strong><\/p>\n<p>Recently, security researchers have announced the details of an exploitable flaw in Ubiquiti&#8217;s wireless networking gear following the manufacturer&#8217;s failure to release a firmware patch. The researchers at Austria&#8217;s <a href=\"https:\/\/www.sec-consult.com\/\">SEC Consult Vulnerability Lab<\/a> discovered the programming error in November and reached out to Ubiquiti through its <a href=\"https:\/\/www.hackerone.com\/\">HackerOne<\/a> hosted big bounty program. At first, <a href=\"https:\/\/www.ubnt.com\/\">Ubiquiti<\/a> denied that this was a new bug but later accepted it. While the manufacturer began working on a patch, Ubiquiti stalled during development. After repeated warnings regarding the bug, SEC decided to go public with the security concerns.<\/p>\n<p>With this bug, hackers can trick someone using a <a href=\"https:\/\/www.ubnt.com\/\">Ubiquiti<\/a> gateway or router into clicking on a malicious link, or embed the URL in a webpage they visit. From there, the hacker could inject commands into the vulnerable device. The networking kit uses the web interface to administer the it\u00a0and lacks CSRF protection meaning that hackers can perform actions as logged-in users. With this vulnerability, attackers can open a reverse shell to establish a connection to a Ubiquiti router and gain root access. The SEC Lab says that once the hacker is inside, the entire network is vulnerable due to a very outdated version (20 years old&#8230;) of PHP included in the software.<\/p>\n<p>&#8220;A command injection vulnerability was found in &#8216;pingtest_action.cgi.&#8217; This script is vulnerable since it is possible to inject a value of a variable. One of the reasons for this behavior is the used PHP version (PHP\/FI 2.0.1 from 1997),&#8221; <a href=\"https:\/\/www.sec-consult.com\/fxdata\/seccons\/prod\/temedia\/advisories_txt\/20170316-0_Ubiquiti_Networks_authenticated_command_injection_v10.txt\" target=\"_blank\" rel=\"nofollow\">SEC&#8217;s advisory today<\/a> states.<\/p>\n<p>&#8220;The vulnerability can be exploited by luring an attacked user to click on a crafted link or just surf on a malicious website. The whole attack can be performed via a single GET-request and is very simple since there is no CSRF protection.&#8221;<\/p>\n<p>SEC tested the attack against four Ubiquiti devices, suspects that another 38 models are similarly vulnerable. Each of the vulnerable devices are listed in the advisory. Proof of Concept exploits, however, were not published and firmware patch still isn&#8217;t available for the devices.<\/p>\n<p><strong><span style=\"color: #ff0000\">Note<\/span>: Ubiquiti has since issued a fix for the vulnerability. Find that <a href=\"https:\/\/community.ubnt.com\/t5\/airMAX-General-Discussion\/AirOS-Vulnerability-Issue-Update-3-18-17\/td-p\/1869309\">here.<\/a><\/strong><\/p>\n<div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><div class=\"box box0\"><h4><a href=\"https:\/\/solutionsreview.com\/wireless-network\/free-80211ac-wireless-network-solutions-buyers-guide\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-1183\" src=\"https:\/\/solutionsreview.com\/wireless-network\/files\/2016\/03\/wireless-guide-cover.png\" alt=\"wireless guide cover\" width=\"140\" height=\"179\" srcset=\"https:\/\/solutionsreview.com\/wireless-network\/files\/2016\/03\/wireless-guide-cover.png 660w, https:\/\/solutionsreview.com\/wireless-network\/files\/2016\/03\/wireless-guide-cover-234x300.png 234w, https:\/\/solutionsreview.com\/wireless-network\/files\/2016\/03\/wireless-guide-cover-211x270.png 211w, https:\/\/solutionsreview.com\/wireless-network\/files\/2016\/03\/wireless-guide-cover-63x81.png 63w, https:\/\/solutionsreview.com\/wireless-network\/files\/2016\/03\/wireless-guide-cover-141x180.png 141w\" sizes=\"(max-width: 140px) 100vw, 140px\" \/><\/a><strong>For information on the top 802.11ac solutions,\u00a0check out our latest Buyer&#8217;s Guide:<\/strong><\/h4>\n<ul>\n<li>Easy, side-by-side comparison of the top 802.11ac wireless vendors<\/li>\n<li>Descriptions of each solution and their strengths<\/li>\n<li>Important questions to ask yourself and potential vendors when considering a solution<\/li>\n<li>Market overview of the current\u00a0802.11ac wireless space<\/li>\n<\/ul>\n<a href=\"https:\/\/solutionsreview.com\/wireless-network\/free-80211ac-wireless-network-solutions-buyers-guide\/\" class=\"ss-button aqua\" target=\"_blank\" rel=\"noopener\">Download Now<\/a><\/div>\n<\/div>\n\t\t<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Note: Ubiquiti has since issued a fix for the vulnerability. Find that here. Recently, security researchers have announced the details of an exploitable flaw in Ubiquiti&#8217;s wireless networking gear following the manufacturer&#8217;s failure to release a firmware patch. The researchers at Austria&#8217;s SEC Consult Vulnerability Lab discovered the programming error in November and reached out [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1788,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"footnotes":"","_jetpack_memberships_contains_paid_content":false,"jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[5,65,66],"tags":[415,413,417,418,416,414,271,385,29],"jetpack_publicize_connections":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Security Flaw Discovered in Ubiquiti Wireless Gear - Best 802.11ac Wireless Networks | WLAN Routers, Switches &amp; Access Point Hardware Reviews<\/title>\n<meta name=\"description\" content=\"Recently, security researchers have announced the details of an exploitable flaw in Ubiquiti&#039;s wireless networking gear following the manufacturer&#039;s failure\u00a0\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Doug Atkinson\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/\",\"url\":\"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/\",\"name\":\"Security Flaw Discovered in Ubiquiti Wireless Gear - Best 802.11ac Wireless Networks | WLAN Routers, Switches &amp; Access Point Hardware Reviews\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/wireless-network\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability.jpg\",\"datePublished\":\"2017-03-17T14:20:31+00:00\",\"dateModified\":\"2017-03-20T19:39:24+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/wireless-network\/#\/schema\/person\/5992f02d38e7b28251ad933cd131dcae\"},\"description\":\"Recently, security researchers have announced the details of an exploitable flaw in Ubiquiti's wireless networking gear following the manufacturer's failure\u00a0\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability.jpg\",\"width\":800,\"height\":350,\"caption\":\"Security Flaw Discovered in Ubiquiti Wireless Gear\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/wireless-network\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security Flaw Discovered in Ubiquiti Wireless Gear\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/wireless-network\/#website\",\"url\":\"https:\/\/solutionsreview.com\/wireless-network\/\",\"name\":\"Best 802.11ac Wireless Networks | WLAN Routers, Switches &amp; Access Point Hardware Reviews\",\"description\":\"Buyers Guide and Best Practices\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/wireless-network\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/wireless-network\/#\/schema\/person\/5992f02d38e7b28251ad933cd131dcae\",\"name\":\"Doug Atkinson\",\"description\":\"An entrepreneur and executive with a passion for enterprise technology, Doug founded Solutions Review in 2012. He has previously served as a newspaper boy, a McDonald's grill cook, a bartender, a political consultant, a web developer, the VP of Sales for e-Dialog - a digital marketing agency - and as Special Assistant to Governor William Weld of Massachusetts.\",\"sameAs\":[\"https:\/\/solutionsreview.com\"],\"url\":\"https:\/\/solutionsreview.com\/wireless-network\/author\/doug-atkinson-4\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Security Flaw Discovered in Ubiquiti Wireless Gear - Best 802.11ac Wireless Networks | WLAN Routers, Switches &amp; Access Point Hardware Reviews","description":"Recently, security researchers have announced the details of an exploitable flaw in Ubiquiti's wireless networking gear following the manufacturer's failure\u00a0","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/","twitter_misc":{"Written by":"Doug Atkinson","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/","url":"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/","name":"Security Flaw Discovered in Ubiquiti Wireless Gear - Best 802.11ac Wireless Networks | WLAN Routers, Switches &amp; Access Point Hardware Reviews","isPartOf":{"@id":"https:\/\/solutionsreview.com\/wireless-network\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability.jpg","datePublished":"2017-03-17T14:20:31+00:00","dateModified":"2017-03-20T19:39:24+00:00","author":{"@id":"https:\/\/solutionsreview.com\/wireless-network\/#\/schema\/person\/5992f02d38e7b28251ad933cd131dcae"},"description":"Recently, security researchers have announced the details of an exploitable flaw in Ubiquiti's wireless networking gear following the manufacturer's failure\u00a0","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/#primaryimage","url":"https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability.jpg","contentUrl":"https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability.jpg","width":800,"height":350,"caption":"Security Flaw Discovered in Ubiquiti Wireless Gear"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/wireless-network\/security-flaw-discovered-in-ubiquiti-wireless-gear\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/wireless-network\/"},{"@type":"ListItem","position":2,"name":"Security Flaw Discovered in Ubiquiti Wireless Gear"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/wireless-network\/#website","url":"https:\/\/solutionsreview.com\/wireless-network\/","name":"Best 802.11ac Wireless Networks | WLAN Routers, Switches &amp; Access Point Hardware Reviews","description":"Buyers Guide and Best Practices","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/wireless-network\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/wireless-network\/#\/schema\/person\/5992f02d38e7b28251ad933cd131dcae","name":"Doug Atkinson","description":"An entrepreneur and executive with a passion for enterprise technology, Doug founded Solutions Review in 2012. He has previously served as a newspaper boy, a McDonald's grill cook, a bartender, a political consultant, a web developer, the VP of Sales for e-Dialog - a digital marketing agency - and as Special Assistant to Governor William Weld of Massachusetts.","sameAs":["https:\/\/solutionsreview.com"],"url":"https:\/\/solutionsreview.com\/wireless-network\/author\/doug-atkinson-4\/"}]}},"jetpack_featured_media_url":"https:\/\/solutionsreview.com\/wireless-network\/files\/2017\/03\/ubiquiti-vulnerability.jpg","jetpack_shortlink":"https:\/\/wp.me\/p2Dlx7-sO","jetpack_sharing_enabled":true,"jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/wireless-network\/wp-json\/wp\/v2\/posts\/1786"}],"collection":[{"href":"https:\/\/solutionsreview.com\/wireless-network\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/wireless-network\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/wireless-network\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/wireless-network\/wp-json\/wp\/v2\/comments?post=1786"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/wireless-network\/wp-json\/wp\/v2\/posts\/1786\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/wireless-network\/wp-json\/wp\/v2\/media\/1788"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/wireless-network\/wp-json\/wp\/v2\/media?parent=1786"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/wireless-network\/wp-json\/wp\/v2\/categories?post=1786"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/wireless-network\/wp-json\/wp\/v2\/tags?post=1786"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}