---
id: CVE-2023-2375
title: A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6
summary: >-
  A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6.
  Impacted is an unknown function of the component Web Management Interface.
  Executing a manipulation of the argument src can lead to command injection. It
  is po…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-74
  - CWE-77
vendor: ui
product: er-x_firmware
affected:
  - er-x_firmware < 2.0.9
  - er-x_firmware = 2.0.9
  - er-x-sfp_firmware < 2.0.9
  - er-x-sfp_firmware = 2.0.9
patched:
  - er-x_firmware 2.0.9
  - er-x-sfp_firmware 2.0.9
published: '2023-04-28'
updated: '2026-07-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-2375'
references:
  - url: 'https://github.com/leetsun/IoT/tree/main/EdgeRouterX/CI/7'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2023-2375'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/114077'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/227651'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/227651/cti'
    label: cna@vuldb.com
  - url: 'https://github.com/leetsun/IoT/tree/main/EdgeRouterX/CI/7'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://vuldb.com/?ctiid.227651'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://vuldb.com/?id.227651'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.09275
epssPercentile: 0.9514
ingestedAt: '2026-07-10T01:55:22.881Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/0x0jr/HTB-Devvortex-CVE-2023-2375-PoC'
  checkedAt: '2026-09-24T07:52:49.756Z'
exploitAvailable: true
---

## Overview

A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. Impacted is an unknown function of the component Web Management Interface. Executing a manipulation of the argument src can lead to command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The presence of this vulnerability remains uncertain at this time. The vendor position is that post-authentication issues are not accepted as vulnerabilities.

## Affected

- `er-x_firmware < 2.0.9`
- `er-x_firmware = 2.0.9`
- `er-x-sfp_firmware < 2.0.9`
- `er-x-sfp_firmware = 2.0.9`

## Remediation

Upgrade past the affected range:

- `er-x_firmware 2.0.9`
- `er-x-sfp_firmware 2.0.9`
