---
id: CVE-2023-2377
title: A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6
summary: >-
  A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6.
  The impacted element is an unknown function of the component Web Management
  Interface. The manipulation of the argument Name results in command injection.
  The at…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-74
  - CWE-77
vendor: ui
product: er-x_firmware
affected:
  - er-x_firmware < 2.0.9
  - er-x_firmware = 2.0.9
  - er-x-sfp_firmware < 2.0.9
  - er-x-sfp_firmware = 2.0.9
patched:
  - er-x_firmware 2.0.9
  - er-x-sfp_firmware 2.0.9
published: '2023-04-28'
updated: '2026-07-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-2377'
references:
  - url: 'https://github.com/leetsun/IoT/tree/main/EdgeRouterX/CI/9'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2023-2377'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/114081'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/227653'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/227653/cti'
    label: cna@vuldb.com
  - url: 'https://github.com/leetsun/IoT/tree/main/EdgeRouterX/CI/9'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://vuldb.com/?ctiid.227653'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://vuldb.com/?id.227653'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.07621
epssPercentile: 0.94296
ingestedAt: '2026-07-10T01:55:22.890Z'
---

## Overview

A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The impacted element is an unknown function of the component Web Management Interface. The manipulation of the argument Name results in command injection. The attack can be launched remotely. The exploit is now public and may be used. There is ongoing doubt regarding the real existence of this vulnerability. The vendor position is that post-authentication issues are not accepted as vulnerabilities.

## Affected

- `er-x_firmware < 2.0.9`
- `er-x_firmware = 2.0.9`
- `er-x-sfp_firmware < 2.0.9`
- `er-x-sfp_firmware = 2.0.9`

## Remediation

Upgrade past the affected range:

- `er-x_firmware 2.0.9`
- `er-x-sfp_firmware 2.0.9`
