Vulnerability record · CVE-2015-9266 · published 5 September 2018
CVE-2015-9266: Ubiquiti airMAX/airOS web interface path traversal file upload to root
Ui · Airmax Ac Firmware
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) permits an unauthenticated attacker to upload and write arbitrary files via directory traversal. Because the written files can be placed where they are executed, the flaw leads to root-level compromise of the device. Fixes were released in July 2015 and all prior versions are affected.
Description
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable path traversal leading to root, with public exploit code and a very high EPSS score, makes this an urgent patch target despite no KEV listing.
What it is
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) permits an unauthenticated attacker to upload and write arbitrary files via directory traversal. Because the written files can be placed where they are executed, the flaw leads to root-level compromise of the device. Fixes were released in July 2015 and all prior versions are affected.
Impact
An attacker gains the ability to write arbitrary files to the device and, by extension, execute code as root. Full control of the affected device follows, including its configuration and any traffic it handles.
Attack surface
Reachable over the network through the device's web management interface; the CVSS vector shows no privileges and no user interaction required. Any host that can reach the management interface can attempt the upload.
Exploitation
Public exploit code exists (Exploit-DB entries and a Rapid7 Metasploit module), and EPSS is very high at roughly 0.74 (99.5th percentile). The CVE is not listed in CISA KEV, so there is no confirmed in-the-wild exploitation record in this data.
What to do
- Upgrade to the fixed firmware versions listed in the advisory (airMAX AC 7.1.3; airMAX M/airRouter 5.6.2 XM/XW/TI, 5.5.11 XM/TI, 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; EdgeSwitch XP 1.3.2).
- Restrict access to the web management interface to trusted management networks only; do not expose it to the internet.
- Segment or firewall management VLANs so untrusted hosts cannot reach the device UI.
- Where the interface cannot be patched immediately, disable remote management access until the upgrade is applied.
Detection
- Monitor web server logs on affected devices for POST requests containing traversal sequences such as ../ in filenames or paths.
- Alert on unexpected file creation or modification in web-served or executable directories on the device.
- Watch for new or unexpected listening services, cron entries, or startup scripts on the device after management interface access.
- Use network monitoring to flag management interface access from hosts outside the expected management subnet.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-9266 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-9266), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.