Impact
The vulnerability centers flaws in the UniFi Talk Application, enabling an attacker with network access and low‑privilege credentials to craft malicious SQL statements. These injection points can be used to elevate the attacker’s privileges on the host device, giving them broader control over the system and potentially its network environment. The weakness corresponds to CWE‑89. No explicit coverage of remote code execution, data diversion, or denial of service is stated in the vendor’s advisory.
Affected Systems
The flaw affects Ubiquiti Inc's UniFi Talk Application. All installed instances could be vulnerable in the absence of explicit version exclusions. Affected version information is not provided in the advisory, so administrators should assume every deployed copy may be impacted until a patch is applied.
Risk and Exploitability
The CVSS issue in the Critical severity range. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploits yet. The attack requires network connectivity and prior access to authenticated low‑privilege credentials; the likely attack vector is thus a network‑based manipulate the application’s SQL queries. Because the exploitation path demands legitimate credentials, the risk is higher in environments that expose the device to untrusted devices or fail to enforce strict account hygiene. No mention of exploitation without prior information is provided.
OpenCVE Enrichment