Impact
UniFi Connect Application has an Improper Access Control flaw (CWE‑284) that permits an attacker who can reach the application over the network to inject arbitrary shell commands. This flaw gives the attacker host‑level privileges, enabling code execution, data exfiltration, or persistence without user interaction.
Affected Systems
All installations of Ubiquiti Inc’s UniFi Connect Application may be affected. The CVE data does not list specific versions or builds, so any deployed instance could be vulnerable.
Risk and Exploitability
The vulnerability scores a CVSS of 10, signifying maximum severity, while the EPSS score of less than 1% suggests a low statistical likelihood of exploitation at present. It is not listed in CISA’s KEV catalog. The likely attack surface consists of any network endpoints that expose the UniFi Connect service without proper authorization checks, allowing a network‑connected actor to send crafted requests and trigger the command injection.
OpenCVE Enrichment