High severity7.2NVD Advisory· Published Apr 28, 2023· Updated Jul 9, 2026
CVE-2023-2374
CVE-2023-2374
Description
A security flaw has been discovered in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This issue affects some unknown processing of the component Web Management Interface. Performing a manipulation of the argument ecn-down results in command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The existence of this vulnerability is still disputed at present. The vendor position is that post-authentication issues are not accepted as vulnerabilities.
Affected products
16cpe:2.3:o:ui:er-x-sfp_firmware:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:o:ui:er-x-sfp_firmware:*:*:*:*:*:*:*:*range: <2.0.9
- cpe:2.3:o:ui:er-x-sfp_firmware:2.0.9:-:*:*:*:*:*:*
- cpe:2.3:o:ui:er-x-sfp_firmware:2.0.9:hotfix2:*:*:*:*:*:*
- cpe:2.3:o:ui:er-x-sfp_firmware:2.0.9:hotfix4:*:*:*:*:*:*
- cpe:2.3:o:ui:er-x-sfp_firmware:2.0.9:hotfix5:*:*:*:*:*:*
- cpe:2.3:o:ui:er-x-sfp_firmware:2.0.9:hotfix6:*:*:*:*:*:*
cpe:2.3:o:ui:er-x_firmware:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:ui:er-x_firmware:*:*:*:*:*:*:*:*range: <2.0.9
- cpe:2.3:o:ui:er-x_firmware:2.0.9:-:*:*:*:*:*:*
- cpe:2.3:o:ui:er-x_firmware:2.0.9:hotfix2:*:*:*:*:*:*
- cpe:2.3:o:ui:er-x_firmware:2.0.9:hotfix3:*:*:*:*:*:*
- cpe:2.3:o:ui:er-x_firmware:2.0.9:hotfix4:*:*:*:*:*:*
- cpe:2.3:o:ui:er-x_firmware:2.0.9:hotfix5:*:*:*:*:*:*
- cpe:2.3:o:ui:er-x_firmware:2.0.9:hotfix6:*:*:*:*:*:*
- Range: <=2.0.9-hotfix.6
<=2.0.9-hotfix.6+ 1 more
- (no CPE)range: <=2.0.9-hotfix.6
- (no CPE)range: 2.0.9-hotfix.0
Patches
Vulnerability mechanics
References
7- github.com/leetsun/IoT/tree/main/EdgeRouterX/CI/6nvdExploitThird Party Advisory
- vuldb.comnvdPermissions RequiredThird Party Advisory
- vuldb.comnvdThird Party Advisory
- vuldb.com/cve/CVE-2023-2374nvd
- vuldb.com/submit/114075nvd
- vuldb.com/vuln/227650nvd
- vuldb.com/vuln/227650/ctinvd
News mentions
0No linked articles in our index yet.