Researchers at SEC Consult disclosed a command injection vulnerability in Ubiquiti Networks gear for ISPs. The vulnerability lives in the pingtest_action.cgi script, which is using PHP/FI 2.0.1 which was built in 1997. The root cause of the vulnerability is the use of a 20-year-old PHP script in the interface, SEC Consult says. Ubiquit Networks says it has patched 37 of the 44 affected products starting Feb. 3 with an update for airMAX 11ac and patches for the remaining products are imminent.
Source: https://threatpost.com/vulnerability-disclosed-in-ubquiti-networks-admin-interface/124392/

