Impact
A vulnerability in UniFi OS allows an attacker who can send crafted input over the network with low privileges and execute arbitrary system commands on the host device. Ability to run commands on the device potentially affects confidentiality, integrity, and availability of the device and its services. Input Validation weakness.
Affected Systems
The flaw affects Ubiquiti devices that run UniFi OS, including Cloud Gateways, Cloud Keys, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewall Core, Enterprise Fortress Gateway, Enterprise Video Recorders, Express 7, Network Attached Storage, Network Video Recorders, and UniFi OS Server. Specific version numbers are not published in the advisory.
Risk and Exploitability
The CVSS score of 9.9 indicates a high severity risk. EPSS score of < 1% indicates a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread active exploitation has been reported. Based on the description, the likely attack vector is a local network where an attacker can reach the device with low privileges, making the vulnerability potentially exploitable under realistic conditions.
OpenCVE Enrichment