A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-middle (MitM) attack during a firmware update. This vulnerability is fixed in EdgeMAX EdgeRouter V2.0.9-hotfix.1 and later.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HUi Edgemax Edgerouter
HWUiall versionsUi Edgemax Edgerouter Firmware
OSUi≤ 2.0.9
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Related vulnerabilities
CVE-2023-31998HIGH7.5same product
A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP ser...
CVE-2023-2373HIGH7.3same product
A vulnerability was identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This vulnerability affects unkno...
CVE-2022-43553HIGH8.8same product
A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious a...
CVE-2026-34908CRITICAL10.0⚠ KEVPL ✓same vendor
Nieprawidłowa kontrola dostępu w UniFi OS — nieautoryzowane zmiany systemowe
CVE-2026-34909CRITICAL10.0⚠ KEVPL ✓same vendor
Path Traversal w UniFi OS — dostęp do plików systemowych i przejęcie konta