CVE-2023-31998: UI Aircube Firmware

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices.

Affected products

  • UI Aircube Firmware: before 2.8.9 (fixed in 2.8.9)
  • UI Edgemax Edgerouter Firmware: version 2.0.9 only

Published 2023-07-18. Last modified 2026-06-17.