Impact
The vulnerability is a Server‑Side Request Forgery (SSRF) that lets an attacker with limited network access send arbitrary internal requests from a UniFi OS device. This flaw, identified as CWE‑918, can enable the attacker to gain full administrative control of the affected device, compromising confidentiality, integrity, and availability of the network infrastructure.
Affected Systems
The flaw impacts all Ubiquiti Inc. UniFi OS-based products, including Cloud Gateways, Cloud Keys, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewall Core, Enterprise Fortress Gateway, Enterprise Video Recorders, Express 7, Network Attached Storage, Network Video Recorders, and the UniFi OS Server. No specific firmware versions are listed, so any current installation is presumed vulnerable until a patched release is applied.
Risk and Exploitability
The CVSS score of 7.7 classifies the issue as high severity, but the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not documented in CISA’s KEV catalog, meaning no known active exploitation has been reported. Based on the description, the most likely attack vector involves a local network actor who already has low privileges using the SSRF capability to issue privileged internal requests; this inference is drawn from the stated requirement for network access and low privileges.
OpenCVE Enrichment