PatchSiren

PatchSiren cyber security CVE debrief

CVE-2010-5330 Ubiquiti CVE debrief

CVE-2010-5330 is a command injection vulnerability in Ubiquiti AirOS. CISA has listed it in the Known Exploited Vulnerabilities catalog, which indicates known real-world exploitation and raises the urgency for remediation. The supplied official sources do not provide affected-version detail or CVSS scoring, so defenders should rely on the KEV listing and vendor guidance referenced by CISA.

Vendor
Ubiquiti
Product
AirOS
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2022-04-15
Original CVE updated
2022-04-15
Advisory published
2022-04-15
Advisory updated
2022-04-15

Who should care

Administrators and asset owners responsible for Ubiquiti AirOS deployments, especially teams managing network infrastructure and internet-facing devices.

Technical summary

The vulnerability is categorized as a command injection issue in Ubiquiti AirOS. In practical terms, command injection flaws can allow attacker-supplied input to be interpreted as system commands. The supplied corpus does not include affected versions, attack prerequisites, or a vendor advisory URL, so the publicly supported takeaway is limited to the vulnerability class and its KEV status.

Defensive priority

High. CISA’s KEV inclusion is a strong indicator that this issue should be treated as urgent for remediation and verification.

Recommended defensive actions

  • Identify all Ubiquiti AirOS assets in your environment.
  • Review the CISA KEV entry and follow the required action to apply updates per vendor instructions.
  • Prioritize exposure reduction for any AirOS systems that are reachable from untrusted networks.
  • Confirm remediation through asset inventory and post-update validation.
  • If immediate patching is not possible, apply compensating controls such as restricting access to management services and monitoring for anomalous command execution or configuration changes.

Evidence notes

The debrief is based only on the supplied official records: the CVE record, NVD detail page, and CISA KEV catalog entry. CISA’s metadata identifies the issue as a Ubiquiti AirOS command injection vulnerability, marks it as known exploited, and states the required action as applying updates per vendor instructions. No additional technical details were taken from outside the provided corpus.

Official resources

CISA added CVE-2010-5330 to the Known Exploited Vulnerabilities catalog on 2022-04-15, with remediation due by 2022-05-06. The supplied records do not include a separate vendor advisory link or affected-version list.