LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2010-5330: Ubiquiti AirOS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 15, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 6, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2010-5330 to its Known Exploited Vulnerabilities catalog on Apr 15, 2022, with a federal patch deadline of May 6, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.

CVE-2010-5330 is a command injection vulnerability in Ubiquiti AirOS that can be triggered by a crafted GET request to the stainfo.cgi endpoint on certain devices. An attacker who can reach that interface may cause the device to run unintended operating-system commands, which can lead to full device compromise, network pivoting, or disruption of wireless infrastructure that depends on AirOS.

Because AirOS commonly runs on outdoor wireless bridges, access points, and backhaul radios, a successful exploit can affect both the device itself and the segments it connects. Confirm exact product models and fixed releases against the vendor advisory before acting.

How it works

The weakness is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command). In this class of flaw, user-controlled input that reaches a command interpreter is not properly sanitized or constrained. According to the public summary, the vulnerable path is a GET request to stainfo.cgi on certain Ubiquiti AirOS devices.

An attacker who can send HTTP requests to the management interface supplies input that the device incorporates into a shell command. If that input contains command separators or other special characters, the device may execute attacker-chosen commands with the privileges of the AirOS process. No further exploit mechanics are provided in the public record; treat any proof-of-concept details as unconfirmed until verified against the vendor advisory and your own lab testing.

Am I affected? How to find it in your systems

Ubiquiti AirOS typically runs on wireless radios, bridges, and access points used for point-to-point links, campus Wi-Fi, and ISP last-mile deployments. These devices are often reachable on management VLANs or, if misconfigured, on the public internet.

How to remediate

Patch first. Apply the updates supplied by Ubiquiti for the affected AirOS releases, following the vendor’s installation instructions exactly. CISA’s required action is to apply updates per vendor instructions; verify the fixed version string after the upgrade.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to command-injection flaws on network appliances.

If your data may have been exposed

Actively exploited vulnerabilities on network devices can lead to broader breaches, credential theft, or lateral movement. If you suspect compromise, isolate the affected radio, preserve logs, and begin incident-response procedures. You can also run a free exposure scan of your email addresses against known breach data sets to check whether associated accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedUbiquiti · AirOS
WeaknessCWE-77
Added to CISA KEVApr 15, 2022
Federal patch deadlineMay 6, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities