Ubiquiti Networks UniFi 5.2.7 does not restrict access to the database, which allows remote attackers to modify the database by directly connecting to it.
References
Link | Resource |
---|---|
https://packetstormsecurity.com/files/138928/Ubiquiti-UniFi-AP-AC-Lite-5.2.7-Improper-Access-Control.html | Exploit Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/93270 |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2017-01-23 13:59
Updated : 2017-01-25 18:59
NVD link : CVE-2016-7792
Mitre link : CVE-2016-7792
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
ubiquiti_networks
- unifi_ap_ac_lite
- unifi_ap_ac_lite_firmware