PatchSiren cyber security CVE debrief
CVE-2010-5330 Ubiquiti CVE debrief
CVE-2010-5330 is a command injection vulnerability in Ubiquiti AirOS. CISA has listed it in the Known Exploited Vulnerabilities catalog, which indicates known real-world exploitation and raises the urgency for remediation. The supplied official sources do not provide affected-version detail or CVSS scoring, so defenders should rely on the KEV listing and vendor guidance referenced by CISA.
- Vendor
- Ubiquiti
- Product
- AirOS
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2022-04-15
- Original CVE updated
- 2022-04-15
- Advisory published
- 2022-04-15
- Advisory updated
- 2022-04-15
Who should care
Administrators and asset owners responsible for Ubiquiti AirOS deployments, especially teams managing network infrastructure and internet-facing devices.
Technical summary
The vulnerability is categorized as a command injection issue in Ubiquiti AirOS. In practical terms, command injection flaws can allow attacker-supplied input to be interpreted as system commands. The supplied corpus does not include affected versions, attack prerequisites, or a vendor advisory URL, so the publicly supported takeaway is limited to the vulnerability class and its KEV status.
Defensive priority
High. CISA’s KEV inclusion is a strong indicator that this issue should be treated as urgent for remediation and verification.
Recommended defensive actions
- Identify all Ubiquiti AirOS assets in your environment.
- Review the CISA KEV entry and follow the required action to apply updates per vendor instructions.
- Prioritize exposure reduction for any AirOS systems that are reachable from untrusted networks.
- Confirm remediation through asset inventory and post-update validation.
- If immediate patching is not possible, apply compensating controls such as restricting access to management services and monitoring for anomalous command execution or configuration changes.
Evidence notes
The debrief is based only on the supplied official records: the CVE record, NVD detail page, and CISA KEV catalog entry. CISA’s metadata identifies the issue as a Ubiquiti AirOS command injection vulnerability, marks it as known exploited, and states the required action as applying updates per vendor instructions. No additional technical details were taken from outside the provided corpus.
Official resources
-
CVE-2010-5330 CVE record
CVE.org
-
CVE-2010-5330 NVD detail
NVD
-
CISA Known Exploited Vulnerabilities catalog
CISA - Apply updates per vendor instructions.
-
Source item URL
cisa_kev
CISA added CVE-2010-5330 to the Known Exploited Vulnerabilities catalog on 2022-04-15, with remediation due by 2022-05-06. The supplied records do not include a separate vendor advisory link or affected-version list.