Description
A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product.
Published: 2026-01-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malicious actor within Wi‑Fi range can trigger remote code execution by sending specially crafted airMAX Wireless Protocol packets. The flaw stems from a buffer overflow and command injection, enabling an attacker to run arbitrary code on the affected device, potentially compromising confidentiality, integrity, and availability of the network operators' infrastructure.

Affected Systems

Ubiquiti products affected are AirMAX AC, AirMAX M, AirFiber AF60, and AirFiber AF60‑XG. All firmware revisions of these units are impacted as the advisory does not specify version limits, implying a system‑wide vulnerability across the product family.

Risk and Exploitability

With a CVSS score of 8.8, the vulnerability is considered high severity. The EPSS score is below 1%, indicating a low likelihood of exploitation at present, and it is not listed in the CISA KEV catalog. The attack vector is remote over the air interface, requiring an adversary to be within wireless proximity of the device.

Generated by OpenCVE AI on August 4, 2026 at 08:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all affected Ubiquiti AirMAX AC, AirMAX M, AirFiber60, and AirFiber AF60‑XG devices to the latest firmware available from the vendor, which incorporates the fix for the airMAX protocol RCE.
  • Confirm that the firmware release notes or security advisories explicitly state that the vulnerability has been remediated before deploying the update.
  • If a firmware update is not yet available, isolate the devices from untrusted wireless traffic, disable the airMAX protocol if possible, and monitor for anomalous packet activity in the device logs.

Generated by OpenCVE AI on August 4, 2026 at 08:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via airMAX Wireless Protocol in Ubiquiti AirMAX and AirFiber Devices

Thu, 30 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product. Affected Products: airMAX AC (Version 8.7.20 and earlier) airMAX M (Version 6.3.22 and earlier) airFiber AF60-XG (Version 1.2.2 and earlier) airFiber AF60 (Version 2.6.7 and earlier) Mitigation: Update your airMAX AC to Version 8.7.21 or later. Update your airMAX M to Version 6.3.24 or later. Update your airFiber AF60-XG to Version 1.2.3 or later. Update your airFiber AF60 to Version 2.6.8 or later. A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product.
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 18 Apr 2026 08:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via airMAX Wireless Protocol in Ubiquiti AirMAX and AirFiber Devices

Wed, 14 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Ui
Ui airfiber Af60
Ui airfiber Af60-xg
Ui airfiber Af60-xg Firmware
Ui airfiber Af60 Firmware
Ui airmax Ac
Ui airmax Ac Firmware
Ui airmax M
Ui airmax M Firmware
CPEs cpe:2.3:h:ui:airfiber_af60-xg:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:airfiber_af60:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:airmax_ac:-:*:*:*:*:*:*:*
cpe:2.3:h:ui:airmax_m:-:*:*:*:*:*:*:*
cpe:2.3:o:ui:airfiber_af60-xg_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ui:airfiber_af60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ui:airmax_ac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ui:airmax_m_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ui
Ui airfiber Af60
Ui airfiber Af60-xg
Ui airfiber Af60-xg Firmware
Ui airfiber Af60 Firmware
Ui airmax Ac
Ui airmax Ac Firmware
Ui airmax M
Ui airmax M Firmware

Fri, 09 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Ubiquiti
Ubiquiti airfiber Af60
Ubiquiti airfiber Af60 Xg
Ubiquiti airmax Ac
Ubiquiti airmax M
Vendors & Products Ubiquiti
Ubiquiti airfiber Af60
Ubiquiti airfiber Af60 Xg
Ubiquiti airmax Ac
Ubiquiti airmax M

Thu, 08 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
Description A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product. Affected Products: airMAX AC (Version 8.7.20 and earlier) airMAX M (Version 6.3.22 and earlier) airFiber AF60-XG (Version 1.2.2 and earlier) airFiber AF60 (Version 2.6.7 and earlier) Mitigation: Update your airMAX AC to Version 8.7.21 or later. Update your airMAX M to Version 6.3.24 or later. Update your airFiber AF60-XG to Version 1.2.3 or later. Update your airFiber AF60 to Version 2.6.8 or later.
References

Subscriptions

Ubiquiti Airfiber Af60 Airfiber Af60 Xg Airmax Ac Airmax M
Ui Airfiber Af60 Airfiber Af60-xg Airfiber Af60-xg Firmware Airfiber Af60 Firmware Airmax Ac Airmax Ac Firmware Airmax M Airmax M Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-30T06:02:49.974Z

Reserved: 2026-01-01T15:00:02.339Z

Link: CVE-2026-21639

cve-icon Vulnrichment

Updated: 2026-01-08T17:21:36.953Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-08T17:15:50.483

Modified: 2026-06-17T10:18:51.413

Link: CVE-2026-21639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T09:00:06Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')