Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in /var/run/beaker/container_file/ are created when providing a valid length payload of 249 characters or fewer to the beaker.session.id cookie in a GET header. The attacker can use a long series of unique session IDs.
Conclusion & alert: CVE-2019-16889 is rated High Exploit Risk (71.9/100): CVSS High severity, with high exploitation likelihood (EPSS 5.09%, 91th percentile). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 11.49% | 5.09% | -6.40% |
| 2 | 2025-11-21 | 9.05% | 11.49% | +2.44% |
| 3 | 2025-11-18 | — | 9.05% | — |
Full EPSS history (15 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.8 | 2.0 | HIGH |
|
10.0 | 6.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| ui | er-x_firmware | < 2.0.3 | cpe:2.3:o:ui:er-x_firmware:*:*:*:*:*:*:*:* |
| ui | er-x-sfp_firmware | < 2.0.3 | cpe:2.3:o:ui:er-x-sfp_firmware:*:*:*:*:*:*:*:* |
| ui | ep-r6_firmware | < 2.0.3 | cpe:2.3:o:ui:ep-r6_firmware:*:*:*:*:*:*:*:* |
| ui | erlite-3_firmware | < 2.0.3 | cpe:2.3:o:ui:erlite-3_firmware:*:*:*:*:*:*:*:* |
| ui | erpoe-5_firmware | < 2.0.3 | cpe:2.3:o:ui:erpoe-5_firmware:*:*:*:*:*:*:*:* |
| ui | er-8_firmware | < 2.0.3 | cpe:2.3:o:ui:er-8_firmware:*:*:*:*:*:*:*:* |
| ui | erpro-8_firmware | < 2.0.3 | cpe:2.3:o:ui:erpro-8_firmware:*:*:*:*:*:*:*:* |
| ui | ep-r8_firmware | < 2.0.3 | cpe:2.3:o:ui:ep-r8_firmware:*:*:*:*:*:*:*:* |
| ui | er-4_firmware | < 2.0.3 | cpe:2.3:o:ui:er-4_firmware:*:*:*:*:*:*:*:* |
| ui | er-6p_firmware | < 2.0.3 | cpe:2.3:o:ui:er-6p_firmware:*:*:*:*:*:*:*:* |
| ui | er-12_firmware | < 2.0.3 | cpe:2.3:o:ui:er-12_firmware:*:*:*:*:*:*:*:* |
| ui | er-8-xg_firmware | < 2.0.3 | cpe:2.3:o:ui:er-8-xg_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://community.ui.com/releases/New-EdgeRouter-firmware-2-0-3-has-been-released-2-0-3/e8badd28-a112-4269-9fb6-ffe3fc0e1643 | Patch Vendor Advisory |
| https://hackerone.com/reports/406614 | Exploit Issue Tracking Third Party Advisory |
| https://mjlanders.com/2019/07/28/resource-consumption-dos-on-edgemax-v1-10-6/ | Exploit Third Party Advisory |