Description
Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free time" Wi-Fi usage by sending a /guest/s/default/ request to obtain a cookie, and then using this cookie in a /guest/s/default/login request with the byfree parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-17046 | Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free time" Wi-Fi usage by sending a /guest/s/default/ request to obtain a cookie, and then using this cookie in a /guest/s/default/login request with the byfree parameter. |
References
| Link | Providers |
|---|---|
| https://www.red4sec.com/cve/unifi.txt |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T05:33:43.796Z
Reserved: 2018-01-07T00:00:00.000Z
Link: CVE-2018-5264
No data.
Status : Modified
Published: 2019-06-07T16:29:00.500
Modified: 2024-11-21T04:08:27.197
Link: CVE-2018-5264
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD