Impact
An Improper Input Validation flaw in the Ubiquiti UniFi Access Application permits a malicious actor with network access and low privileges to inject and execute arbitrary system commands on the host device, effectively enabling full compromise of that device.
Affected Systems
All installations of Ubiquiti Inc’s UniFi Access Application are potentially vulnerable; the advisory does not identify a specific version range, indicating that any platform running the application could be affected.
Risk and Exploitability
The CVSS score of 9.9 classifies the vulnerability as critical, yet the EPSS score of less than 1% suggests a low likelihood of active exploitation at present. The attack requires the attacker to be on the same network and possess low-privilege access, making any host within the same LAN a potential attack vector. The vulnerability is not listed in the CISA KEV catalog, but the severity warrants prompt remediation.
OpenCVE Enrichment