Ubiquiti EdgeMAX EdgeSwitch Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in Ubiquiti EdgeMAX EdgeSwitch versions through 1.10.4. This vulnerability arises from improper input validation, potentially allowing a malicious actor with access to the adjacent network to execute arbitrary commands on the device.

Impact

Exploitation of this vulnerability could lead to unauthorized command execution on the affected EdgeSwitch device.

Remediation

Users are advised to update EdgeMAX EdgeSwitch to version 1.11.0 or later.

Added: Aug 4, 2025, 11:26 PM
Updated: Aug 4, 2025, 11:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.9
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.