CVE-2025-48978

7.5

Ubiquiti Inc · EdgeMAX EdgeSwitch

An improper input validation vulnerability in Ubiquiti EdgeMAX EdgeSwitch allows command injection by an attacker with access to an adjacent network.

Executive summary

A command injection vulnerability in Ubiquiti EdgeMAX EdgeSwitch poses a severe risk of unauthorized system control by adjacent attackers.

Vulnerability

This is a command injection flaw resulting from improper input validation. The vulnerability is exploitable by an unauthenticated attacker who maintains access to the same local network as the switch.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high severity risk. Successful exploitation grants an attacker the ability to execute arbitrary commands on the affected network hardware, potentially leading to a complete compromise of the device, lateral movement into the protected network segments, or sustained denial of service.

Remediation

Immediate Action: Update the firmware of all affected EdgeMAX EdgeSwitch devices to version 1.11.1 or later as specified in the official vendor advisory.

Proactive Monitoring: Monitor network traffic for unusual management protocol activity or unexpected command execution attempts originating from local adjacent clients.

Compensating Controls: Restrict access to the switch management interface to trusted, isolated management VLANs and utilize strict network access control lists to limit who can reach the device from the local network.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Given the high CVSS score and the critical nature of network infrastructure, administrators should prioritize updating these devices to version 1.11.1 immediately. Failure to apply this patch exposes the core network to potential takeover by any actor capable of reaching the local network segment.

More Ubiquiti Inc CVEs

Sources