2020-05-06 17:15
Ubiquiti
Alex Lowe

Ubiquiti releases new USG firmware, version 4.4.51

Ubiquiti releases new USG firmware, version 4.4.51

Today, Ubiquiti has released a new firmware update for the UniFi Security Gateway line of devices. Version 4.4.51 has already been pushed to controllers and fixes quite an important security issues, one was where attackers could crash the PPPoE process on the USG, so long as the attackers is on the same broadcast domain.

Version 4.4.51 is now out for the USG-3P, USG Pro 4 and the now discontinued USG-XG.

Release Notes

Important notes

The PPPoE client security update fixes a vulnerability that allows an attacker on the same broadcast domain as your WAN to crash the pppd process, and may allow code execution on the system. Attempts at code execution are extremely unlikely to succeed from what is currently known, particularly since many attempts are likely to be required, and each attempt will crash pppd leaving you disconnected from the Internet until rebooting USG. The same broadcast domain requirement means compromising your DSL modem or ISP’s equipment is required to even attempt to do so. It is not exploitable from the Internet, nor from internal networks. While the immediate risk is minimal, we recommend all PPPoE users upgrade as soon as practical, in case a reliable code execution exploit is developed and ISPs and/or DSL modems start getting compromised to exploit it.

Bugfixes

  • Properly handle RADIUS server user passwords containing quotes and backslashes.
  • Update PPPoE client with CVE-2020-8597 security patch.

Source: Ubiquiti

Alex Lowe

Ubiquiti releases new USG firmware, version 4.4.51

Alex Lowe is the owner and editor of the interface and started the website in 2013. He publishes the majority of the content on the website, hosts the three podcasts and the runs the YouTube channels. Alex has a professional background in computer networking, FWA and WiFi.

Other Posts

Ubiquiti launches UniFi Building Bridge – a managed 60GHz PtP kit
The new UBB allows speeds of up to 1.7Gbps and has a 5Ghz backup radio
Ubiquiti debuts new UniFi U6 Mesh Pro
New updated UniFi U6 Mesh Pro takes the old AC Mesh Pro further, now with WiFi 6 support
Ubiquiti launches the U7 Pro, the first 802.11be UniFi AP
The fist WIFi 7 (802.11be) AP is now out from Ubiquiti, with a 2.5GbE PoE port and $189 price tag
Ubiquiti announces Wave MLO, its next generation PtMP system for 5GHz and 6GHz
Ubiquiti announces brand new PtMP system for both 5GHz and 6GHz with Wave MLO