A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with an operator account to run arbitrary administrator commands.This vulnerability is fixed in Version 2.0.9-hotfix.5 and later.
2022-12-05T22:15:11.037
2025-04-24T14:15:38.510
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | ui | edgemax_edgerouter_firmware | < 2.0.9 | Yes |
Operating System | ui | edgemax_edgerouter_firmware | 2.0.9 | Yes |
Operating System | ui | edgemax_edgerouter_firmware | 2.0.9 | Yes |
Operating System | ui | edgemax_edgerouter_firmware | 2.0.9 | Yes |
Operating System | ui | edgemax_edgerouter_firmware | 2.0.9 | Yes |
Hardware | ui | edgemax_edgerouter | - | No |