Impact
An authenticated NoSQL Injection flaw exists in Ubiquiti’s UniFi Network Application, enabling an attacker who has valid credentials to inject arbitrary database queries. The vulnerability, classified under CWE-943, allows escalation of privileges, potentially granting the attacker elevated access and control over the network’s management functions. According to the vendor’s description, an attacker could modify data and access sensitive information or execute further malicious actions on the affected device.
Affected Systems
The flaw affects Ubiquiti Inc’s UniFi Network Application. No specific version information has been supplied in the advisory, indicating that all current releases may be susceptible until a patch is released. Users should verify whether their deployed version is impacted by reviewing the vendor’s support pages or release notes.
Risk and Exploitability
The CVSS score of 7.7 categorizes this vulnerability as high severity. While EPSS data is not available, the requirement for authenticated access limits its exploitation to insiders or compromised credentials rather than remote attackers. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed public exploits to date. Nonetheless, the potential for privilege escalation warrants immediate attention and remediation once a vendor fix becomes available.
OpenCVE Enrichment