PatchSiren

PatchSiren cyber security CVE debrief

CVE-2010-5330 Ubiquiti CVE debrief

CVE-2010-5330 is a command injection vulnerability in Ubiquiti AirOS. CISA has listed it in the Known Exploited Vulnerabilities catalog, which indicates known real-world exploitation and raises the urgency for remediation. The supplied official sources do not provide affected-version detail or CVSS scoring, so defenders should rely on the KEV listing and vendor guidance referenced by CISA.

Vendor
Ubiquiti
Product
AirOS
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2022-04-15
Original CVE updated
2022-04-15
Advisory published
2022-04-15
Advisory updated
2022-04-15

Who should care

Administrators and asset owners responsible for Ubiquiti AirOS deployments, especially teams managing network infrastructure and internet-facing devices.

Technical summary

The vulnerability is categorized as a command injection issue in Ubiquiti AirOS. In practical terms, command injection flaws can allow attacker-supplied input to be interpreted as system commands. The supplied corpus does not include affected versions, attack prerequisites, or a vendor advisory URL, so the publicly supported takeaway is limited to the vulnerability class and its KEV status.

Defensive priority

High. CISA’s KEV inclusion is a strong indicator that this issue should be treated as urgent for remediation and verification.

Recommended defensive actions

  • Identify all Ubiquiti AirOS assets in your environment.
  • Review the CISA KEV entry and follow the required action to apply updates per vendor instructions.
  • Prioritize exposure reduction for any AirOS systems that are reachable from untrusted networks.
  • Confirm remediation through asset inventory and post-update validation.
  • If immediate patching is not possible, apply compensating controls such as restricting access to management services and monitoring for anomalous command execution or configuration changes.

Evidence notes

The debrief is based only on the supplied official records: the CVE record, NVD detail page, and CISA KEV catalog entry. CISA’s metadata identifies the issue as a Ubiquiti AirOS command injection vulnerability, marks it as known exploited, and states the required action as applying updates per vendor instructions. No additional technical details were taken from outside the provided corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2010-5330 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2010-5330

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2010-5330 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2010-5330

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.