CRITICAL CISA KEV

CVE-2010-5330

CVSS v3

9.8

CRITICAL

EPSS Score

56.5%

exploit probability

CISA KEV

Yes

known exploited

Exploitation

SSVC status

Description

On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected.

CISA Known Exploited Vulnerability

Date Added
4/15/2022
Patch Due Date
5/6/2022
Ransomware Use
Unknown

Technical details

Published
6/11/2019

Frequently asked questions

What is CVE-2010-5330?

On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected.

Is CVE-2010-5330 actively exploited?

Yes. CVE-2010-5330 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 5/6/2022.

What is the CVSS score for CVE-2010-5330?

CVE-2010-5330 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2010-5330 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

Other 2010 vulnerabilities worth triaging

Ranked by exploit probability (EPSS).