BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Root From Kilometers Away: Ubiquiti AirMax RCE\n   T
 ags: DEF CON Official Talk | Demo ðŸ’» | Tool ðŸ›  | Exploit ðŸª²\n   When
 : Saturday\, Aug 8\, 10:30 - 11:30 PDT\n   Where: LVCCW Level 1 Hall 3 904
  (Main Track 4) and DCTV-4 - [1]Map\n\n   Description:\n\n   You don't rea
 lize it until you see them\; they're everywhere. From\n   Wireless ISP lin
 ks to the frontline of modern warfare. But nobody\n   found anything? The 
 devices behind those links are Ubiquiti AirMAX:\n   critical infrastructur
 e on a 17-year-old Linux kernel and a custom\n   802.11 extension built on
  "security by obscurity." So we took it\n   apart. This talk covers our re
 verse engineering of the AirMAX\n   protocol\, AirOS\, and the kernel modu
 les behind this proprietary mode.\n   It rides on 802.11 Information Eleme
 nts that look encrypted\, but we'll\n   show why they aren't. What we foun
 d: two critical vulnerabilities\n   (CVE-2026-21639\, CVE-2026-21638) acro
 ss airMAX AC\, airMAX M\, airFiber\,\n   and GigaBeam\, over 50 devices. T
 hese are the bugs from the movies:\n   Over-The-Air\, unauthenticated\, ke
 rnel-privilege RCE. No network\n   access\, just line of sight. They affec
 t every AirMAX device ever\n   shipped. We disclosed them through Ubiquiti
 's bug bounty program. The\n   bugs were rated "Adjacent"\, except adjacen
 t here means kilometers\n   away. The same hardware can be turned around a
 nd pointed at the\n   problem: we'll repurpose these devices as recon tool
 s and release\n   open-source software to locate AirMAX networks in the wi
 ld. This talk\n   is about our journey\, our tooling\, and the state of se
 curity.\n\n   Speakers:Federico Kirschbaum\,Gaston Aznarez\n\n   SpeakerBi
 o:  Federico Kirschbaum\, FaradaySec\n\n   Federico Kirschbaum is a securi
 ty researcher with over two decades of\n   experience building tools and e
 cosystems for offensive security. He is\n   the Co-Founder and VP of Resea
 rch in Faraday Security\, an open-source\n   platform. He is also the Co-F
 ounder of Ekoparty\, Latin Americaâ€™s\n   largest hacking conference\, wh
 ere he has helped shape the regionâ€™s\n   security research community for
  over 20 years.\n\n   SpeakerBio:  Gaston Aznarez\, FaradaySec\n\n   Gasto
 n Aznarez is a Principal Security Researcher at Faraday Security\,\n   foc
 used on IoT and embedded device vulnerability research\, firmware\n   reve
 rse engineering\, wireless protocol analysis\, and hardware-level\n   expl
 oitation. He has presented at DEF CON\, Black Hat and Ekoparty.\n\n   '\n\
 n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260808T183000Z
DTSTART:20260808T173000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4
SUMMARY:Root From Kilometers Away: Ubiquiti AirMax RCE
END:VEVENT
END:VCALENDAR
