Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / Unpatched vulnerability places Ubiquiti networking merchandise at chance

Unpatched vulnerability places Ubiquiti networking merchandise at chance

Latest Govt. Jobs 13:27:00 News Edit
ubiquiti rocket m base station

An unpatched command injection vulnerability could allow hackers to take over enterprise networking products from Ubiquiti Networks.
The vulnerability was discovered by researchers from SEC Consult and allows authenticated users to inject arbitrary commands into the web-based administration interface of affected devices. These commands would be executed on the underlying operating system as root, the highest privileged account.
Because it requires authentication, the vulnerability's impact is somewhat reduced, but it can still be exploited remotely through cross-site request forgery (CSRF). This is an attack technique that involves forcing a user's browser to send unauthorized requests to specifically crafted URLs in the background when they visit attacker-controlled websites.
[ Further reading: How the new age of antivirus software will protect your PC ]
"The vulnerability can be exploited by luring an attacked user to click on a crafted link or just surf on a malicious website," the SEC Consult researchers said in an advisory Thursday. "The whole attack can be performed via a single GET-request and is very simple since there is no CSRF protection."
Attackers have used CSRF-based attacks before to compromise home routers en masse and change their DNS settings. These attacks are known as router pharming.
By exploiting this vulnerability attackers can open a so-called reverse shell on the affected devices, which would allow them to execute further commands and install malware or launch attacks against computers or servers on the internal network.
The SEC Consult researchers have tested the exploit successfully on four Ubiquiti Networks devices: TS-8-PRO, M5 (Rocket), PICOM2HP (PicoStationM2HP), and NSM5 (NanoStationM5). However, after an automated analysis of other firmware packages, they believe an additional 38 device models could be affected.
According to them, the vulnerability was reported to Ubiquity on Nov. 22 and the vendor acknowledged the flaw. However, there has been no further communications from Ubiquity since Jan. 24, despite repeated calls for a status update, so SEC Consult decided to publish the advisory.
The researchers have held back from releasing a proof-of-concept exploit for now, but they have named the vulnerable firmware component, which could allow other researchers or even malicious hackers to locate the flaw on their own.
Ubiquity Networks did not immediately respond to a request for comment.
In the absence of a fix, users are advised to restrict access to the administration interface of Ubiquity devices, even from local networks.
This flaw should also serve as a reminder not to leave active logged-in sessions for routers and other networking devices inside browsers. Some Ubiquity devices allow the creation of lower privileged accounts, which can be used to exploit this vulnerability as well.
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


Xiaomi Redmi 5 with 18:9 display

Vivo V9 with dual rear cameras

Xiaomi Redmi 5 launch
Unpatched vulnerability places Ubiquiti networking merchandise at chance Unpatched vulnerability places Ubiquiti networking merchandise at chance Reviewed by Latest Govt. Jobs on 13:27:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows 10 Creators Update is here, now—yes,  now —but not (officially) on the PC. The ...
  • Taotronics TT-BH22 Headphones Review
    We make it a addiction to now not look up pricing of a product sooner than reviewing and if ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on Monday strongly condemned North Korea’s latest missile test, adding that the ...
  • Jio effect: Telcos may have to cut data rates 2017
    India's big  telecom  companies,  Bharti Airtel ,  Vodafone India  and  Idea Cellular , will be ...
  • Bank wallets growing faster than e-wallets
    In the  bank  versus  e-wallets  sweepstakes,  lenders  have now gained lost ground. As of ...

Random Posts

  • HP revs up Z4 workstation
    HP revs up Z4 workstation
    07.02.2018 - 0 Comments
    HP Z4 Workstation is now available with a starting price of ,499. (Image Source: HP) HP on Tuesday…
  • Vizio's entry-level 4K TVs finally make HDR affordable
    Vizio's entry-level 4K TVs finally make HDR affordable
    04.03.2017 - 0 Comments
    Vizio's a pioneer when it comes to making TVs with high-end features at low-end prices. The company…
  • China's Baidu opens augmented reality lab in Beijing
    China's Baidu opens augmented reality lab in Beijing
    16.01.2017 - 0 Comments
    BEIJING: Chinese search engine Baidu on Monday launched an augmented reality (AR) lab in Beijing as…
  • Apple Watch Review
    Apple Watch Review
    12.02.2017 - 0 Comments
    Apple VERDICT Apple Watch is good, but better suited on the wrists of early adopters and boutique shop…
  • Helpchat Zomato Offer – Get 50% Cashback on First Food Order using Helpchat   [ ultimateztricks.com ]
    Helpchat Zomato Offer – Get 50% Cashback on First Food Order using Helpchat [ ultimateztricks.com ]
    15.03.2016 - 0 Comments
    Helpchat Zomato Offer – It’s time to give treats to your friends as Helpchat is now offering amazing new…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Reliance Jio set to charge subscribers from April 1,2017
    India's mobile-telephony companies are headed for a fresh round of price wars after the country's ...
  • Steam Now Supports PS4's DualShock 4 Controller
    HIGHLIGHTS ...
  • Hands-on: HP's Lap Dock helps your Windows Phone feel more like a real PC
    HP’s Lap Dock ...
  • Jio effect: Telcos may have to cut data rates 2017
    India's big  ...
  • WhatsApp, Telegram patch flaws in instant messaging applications
    WhatsApp and ...
  • Lenovo HW02 Plus fitness band Review
    Lenovo HW02 Plus ...
  • How to Make a Long Distance Relationship Work?
    Long distance ...

Random Posts

  • Top 5 functions of the Sony Xperia XZs
    Top 5 functions of the Sony Xperia XZs
    03.04.2017 - 0 Comments
    The Sony Xperia XZs was originally launched during the MWC over a month ago. The handset…
  • Find out Paint.net – the quality free software for retouching portrait images
    Find out Paint.net – the quality free software for retouching portrait images
    06.04.2017 - 0 Comments
    Retouching portrait photos is often referred to as 'Photoshopping', but you don't need to splash out…
  • Everything we think we know about the Galaxy S8
    Everything we think we know about the Galaxy S8
    07.03.2017 - 0 Comments
    Update 3/6: This article has been updated with new images, as well as information on the…
  • BILLION CAPTURE PLUS (32GB )
    BILLION CAPTURE PLUS (32GB )
    23.01.2018 - 0 Comments
    The Billion Capture Plus 32GB mobile features a 5.5" (13.97 cm) display with a screen resolution of Full HD…
  • 17 Must-See Movies to Watch with Your Boyfriend
    17 Must-See Movies to Watch with Your Boyfriend
    28.09.2016 - 0 Comments
    Here’s a list of the best when it comes to movies to watch with your boyfriend. They’ll rekindle your love…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!