CVE-2020-8171 is a critical command injection vulnerability affecting Ubiquiti AirMax AirOS firmware versions 6.2.0 and prior for TI, XW, and XM boards. An unauthenticated attacker can craft a malicious input string to bypass filters, leading to remote code execution. With a CVSS score of 9.8 (Critical), this vulnerability allows for complete compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, immediate patching to AirOS firmware v6.3.0 or later is strongly recommended due to the high severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.2.0CPE matchmatch criteria | cpe:2.3:o:ui:airos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.