Ubiquiti device command injection vulnerability granting root access

  • Who's gonna be first to rent a jet ski and go wardriving past Troy Hunt's house? (warsailing? warskiing?)

  • A 1997 vintage version of PHP??? _Really?_ Ouch!

    (Also, check out the Vendor contact timeline bit)

  • Remotely exploitable with a single GET request. Affects the vast majority of Ubiquiti devices.