CVE-2025-48978
7.5Ubiquiti Inc · EdgeMAX EdgeSwitch
An improper input validation vulnerability in Ubiquiti EdgeMAX EdgeSwitch allows command injection by an attacker with access to an adjacent network.
Executive summary
A command injection vulnerability in Ubiquiti EdgeMAX EdgeSwitch poses a severe risk of unauthorized system control by adjacent attackers.
Vulnerability
This is a command injection flaw resulting from improper input validation. The vulnerability is exploitable by an unauthenticated attacker who maintains access to the same local network as the switch.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk. Successful exploitation grants an attacker the ability to execute arbitrary commands on the affected network hardware, potentially leading to a complete compromise of the device, lateral movement into the protected network segments, or sustained denial of service.
Remediation
Immediate Action: Update the firmware of all affected EdgeMAX EdgeSwitch devices to version 1.11.1 or later as specified in the official vendor advisory.
Proactive Monitoring: Monitor network traffic for unusual management protocol activity or unexpected command execution attempts originating from local adjacent clients.
Compensating Controls: Restrict access to the switch management interface to trusted, isolated management VLANs and utilize strict network access control lists to limit who can reach the device from the local network.
Exploitation status
Public Exploit Available: False
Analyst recommendation
Given the high CVSS score and the critical nature of network infrastructure, administrators should prioritize updating these devices to version 1.11.1 immediately. Failure to apply this patch exposes the core network to potential takeover by any actor capable of reaching the local network segment.