Impact
A malicious actor within Wi‑Fi range can trigger remote code execution by sending specially crafted airMAX Wireless Protocol packets. The flaw stems from a buffer overflow and command injection, enabling an attacker to run arbitrary code on the affected device, potentially compromising confidentiality, integrity, and availability of the network operators' infrastructure.
Affected Systems
Ubiquiti products affected are AirMAX AC, AirMAX M, AirFiber AF60, and AirFiber AF60‑XG. All firmware revisions of these units are impacted as the advisory does not specify version limits, implying a system‑wide vulnerability across the product family.
Risk and Exploitability
With a CVSS score of 8.8, the vulnerability is considered high severity. The EPSS score is below 1%, indicating a low likelihood of exploitation at present, and it is not listed in the CISA KEV catalog. The attack vector is remote over the air interface, requiring an adversary to be within wireless proximity of the device.
OpenCVE Enrichment