Impact
The vulnerability is a Server‑Side Request Forgery that allows an attacker who has only limited network access and low privileges to send arbitrary internal requests from a UniFi OS device. The flaw, known as CWE‑918, can cause the attacker to gain administrative control over the device, thereby compromising the confidentiality, integrity, and availability of the network infrastructure.
Affected Systems
All Ubiquiti Inc. Uni Recorders, Express‑7, Network Attached Storage, Network Video Recorders, and the UniFi OS Server—is vulnerable. No specific firmware versions are listed, so any current installation is presumed at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 7.7 classifies the issue as high severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog, meaning no publicly documented exploitation is known. Based on the requirement for network and low‑privilege access, the most likely attack vector involves a local network actor leveraging the SSRF path to issue privileged internal requests from the device.
OpenCVE Enrichment