A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HUi Aircube
HWUiall versionsUi Aircube Firmware
OSUi< 2.8.9Ui Edgemax Edgerouter
HWUiall versionsUi Edgemax Edgerouter Firmware
OSUi2.0.9
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Memory
Related vulnerabilities
CVE-2023-2373HIGH7.3same product
A vulnerability was identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This vulnerability affects unkno...
CVE-2022-43553HIGH8.8same product
A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious a...
CVE-2021-22909HIGH7.5same product
A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-...
CVE-2026-34908CRITICAL10.0⚠ KEVPL ✓same vendor
Nieprawidłowa kontrola dostępu w UniFi OS — nieautoryzowane zmiany systemowe
CVE-2026-34909CRITICAL10.0⚠ KEVPL ✓same vendor
Path Traversal w UniFi OS — dostęp do plików systemowych i przejęcie konta