Impact
An Improper Input Validation flaw in the Ubiquiti UniFi Access Application permits a malicious actor with network access and low privileges to inject and execute arbitrary system commands on the host device, effectively enabling full compromise of that device.
Affected Systems
All installations of Ubiquiti Inc’s UniFi Access Application are potentially vulnerable; the advisory does not identify a specific version range, indicating that any platform running the application could be affected.
Risk and Exploitability
The CVSS score of 9.9 classifies the vulnerability as critical, yet the EPSS score of approximately 1.2% indicates a low likelihood of active exploitation at present. The likely attack vector is a network‑based attacker on the same LAN, inferred from the requirement that the attacker have network access and low‑privilege access, making any host within that LAN a potential target. The vulnerability is not listed in the CISA KEV catalog, but the severity warrants prompt remediation.
OpenCVE Enrichment