Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / Unpatched vulnerability places Ubiquiti networking merchandise at chance

Unpatched vulnerability places Ubiquiti networking merchandise at chance

Latest Govt. Jobs 13:27:00 News Edit
ubiquiti rocket m base station

An unpatched command injection vulnerability could allow hackers to take over enterprise networking products from Ubiquiti Networks.
The vulnerability was discovered by researchers from SEC Consult and allows authenticated users to inject arbitrary commands into the web-based administration interface of affected devices. These commands would be executed on the underlying operating system as root, the highest privileged account.
Because it requires authentication, the vulnerability's impact is somewhat reduced, but it can still be exploited remotely through cross-site request forgery (CSRF). This is an attack technique that involves forcing a user's browser to send unauthorized requests to specifically crafted URLs in the background when they visit attacker-controlled websites.
[ Further reading: How the new age of antivirus software will protect your PC ]
"The vulnerability can be exploited by luring an attacked user to click on a crafted link or just surf on a malicious website," the SEC Consult researchers said in an advisory Thursday. "The whole attack can be performed via a single GET-request and is very simple since there is no CSRF protection."
Attackers have used CSRF-based attacks before to compromise home routers en masse and change their DNS settings. These attacks are known as router pharming.
By exploiting this vulnerability attackers can open a so-called reverse shell on the affected devices, which would allow them to execute further commands and install malware or launch attacks against computers or servers on the internal network.
The SEC Consult researchers have tested the exploit successfully on four Ubiquiti Networks devices: TS-8-PRO, M5 (Rocket), PICOM2HP (PicoStationM2HP), and NSM5 (NanoStationM5). However, after an automated analysis of other firmware packages, they believe an additional 38 device models could be affected.
According to them, the vulnerability was reported to Ubiquity on Nov. 22 and the vendor acknowledged the flaw. However, there has been no further communications from Ubiquity since Jan. 24, despite repeated calls for a status update, so SEC Consult decided to publish the advisory.
The researchers have held back from releasing a proof-of-concept exploit for now, but they have named the vulnerable firmware component, which could allow other researchers or even malicious hackers to locate the flaw on their own.
Ubiquity Networks did not immediately respond to a request for comment.
In the absence of a fix, users are advised to restrict access to the administration interface of Ubiquity devices, even from local networks.
This flaw should also serve as a reminder not to leave active logged-in sessions for routers and other networking devices inside browsers. Some Ubiquity devices allow the creation of lower privileged accounts, which can be used to exploit this vulnerability as well.
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


Xiaomi Redmi 5 with 18:9 display

Vivo V9 with dual rear cameras

Xiaomi Redmi 5 launch
Unpatched vulnerability places Ubiquiti networking merchandise at chance Unpatched vulnerability places Ubiquiti networking merchandise at chance Reviewed by Latest Govt. Jobs on 13:27:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • Taotronics TT-BH22 Headphones Review
    We make it a addiction to now not look up pricing of a product sooner than reviewing and if ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows 10 Creators Update is here, now—yes,  now —but not (officially) on the PC. The ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on Monday strongly condemned North Korea’s latest missile test, adding that the ...
  • Fitbit Zip 2017 review
    Fitbit PROS: Clever, accurate tracking Expandable online service Integration with 3rd ...

Random Posts

  • Now available at Rs 999 Reliance JioFi device gets 50 per cent discount
    Now available at Rs 999 Reliance JioFi device gets 50 per cent discount
    23.09.2017 - 0 Comments
    Reliance Jio JioFi will be available at Rs 999 from September 20 to September 30 under company’s festive…
  • Lenovo K8 Plus 3GB RAM Smartphone
    Lenovo K8 Plus 3GB RAM Smartphone
    26.01.2018 - 0 Comments
    The Lenovo K8 Plus mobile features a 5.2" (13.21 cm) display with a screen resolution of Full HD (1080 x…
  •  Snapchat's got the kids For advertisers
    Snapchat's got the kids For advertisers
    13.02.2018 - 0 Comments
    SAN FRANCISCO: Social network Instagram has come to look more like rival Snapchat after copying some of…
  • SAP sets March 30 as launch date for its Cloud Platform SDK for iOS
    SAP sets March 30 as launch date for its Cloud Platform SDK for iOS
    27.02.2017 - 0 Comments
    Almost a year after SAP teamed with Apple to develop business applications for smartphones and tablets,…
  • Latest  Apple's MEGA iPhone 8 Update Takes Shape: Specs, New Design & Release Date News
    Latest Apple's MEGA iPhone 8 Update Takes Shape: Specs, New Design & Release Date News
    10.03.2017 - 0 Comments
    Apple's iPhone 8 will get a release date inside Q3 2017... below is ALL the latest iPhone 8 release…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows ...
  • Taotronics TT-BH22 Headphones Review
    We make it a ...
  • Paytm Hostel Booking Offer HTL40 – Get 40% cashback On No Minimum Order Value (2 Times)
    Paytm Paytm Hostel ...
  • RBI's cellular wallet interoperability faces few hurdles
    Adding a new ...
  • Here Government launches cyber security services to keep you safe from malware
    The  Indian ...
  • Latest Blackberry KEYone on website, spills out price and other details
    China-based  ...

Random Posts

  • The Best Ghost Hunting Apps All Ghost Chasers Must Have on their Android Phone
    The Best Ghost Hunting Apps All Ghost Chasers Must Have on their Android Phone
    23.11.2016 - 0 Comments
    There are two kinds of people in the world: those who have had a paranormal experience and are entirely…
  • New Mass Effect: release date, news and rumors
    New Mass Effect: release date, news and rumors
    10.03.2017 - 0 Comments
    Updated: Though it's been confirmed that the game's multiplayer maps will be free looks like…
  • 50 Flirty Text Messages that Are Sure to Make Her Smile
    50 Flirty Text Messages that Are Sure to Make Her Smile
    27.04.2016 - 0 Comments
    The age of text message flirting is here and thriving. Are you armed with the perfect lines to woo that…
  • Here Paytm + BuyHatke Offer: Pay 1Rs. And Get 10Rs. Cashback With Buy Hatke Extension
    Here Paytm + BuyHatke Offer: Pay 1Rs. And Get 10Rs. Cashback With Buy Hatke Extension
    03.03.2017 - 0 Comments
    Paytm + BuyHatke Offer: BuyHatke offering Rs 10 Paytm cash for Installing their extension. you have…
  • Truebalance App – Download And Get Rs 20 Free Recharge (All India)
    Truebalance App – Download And Get Rs 20 Free Recharge (All India)
    20.04.2016 - 0 Comments
    Truebalance app gives you one touch solution to manage your prepaid mobile balances. Not only checking…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!