Description
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
Published: 2026-07-02
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in UniFi OS allows an attacker who can send crafted input over the network with low privileges and execute arbitrary system commands on the host device. Ability to run commands on the device potentially affects confidentiality, integrity, and availability of the device and its services. Input Validation weakness.

Affected Systems

The flaw affects Ubiquiti devices that run UniFi OS, including Cloud Gateways, Cloud Keys, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewall Core, Enterprise Fortress Gateway, Enterprise Video Recorders, Express 7, Network Attached Storage, Network Video Recorders, and UniFi OS Server. Specific version numbers are not published in the advisory.

Risk and Exploitability

The CVSS score of 9.9 indicates a high severity risk. EPSS score of < 1% indicates a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread active exploitation has been reported. Based on the description, the likely attack vector is a local network where an attacker can reach the device with low privileges, making the vulnerability potentially exploitable under realistic conditions.

Generated by OpenCVE AI on July 22, 2026 at 13:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest UniFi OS firmware update from Ubiquiti to all affected devices.
  • If the devices are in separate network segments, restrict local user permissions to limit the ability to execute system commands.
  • Continuously monitor device logs for anomalous command execution and enforce strict input validation policies where possible.

Generated by OpenCVE AI on July 22, 2026 at 13:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Input Validation in UniFi OS

Fri, 17 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Input Validation in UniFi OS

Thu, 16 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Command injection via Improper Input Validation in UniFi OS

Tue, 14 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Command injection via Improper Input Validation in UniFi OS

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Input Validation in UniFi OS Devices

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Input Validation in UniFi OS Devices

Fri, 10 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Command injection via improper input validation in UniFi OS devices

Thu, 09 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Command injection via improper input validation in UniFi OS devices

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Command Injection Vulnerability in UniFi OS via Improper Input Validation

Wed, 08 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Command Injection Vulnerability in UniFi OS via Improper Input Validation

Tue, 07 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Improper Input Validation Allows Command Injection on UniFi OS Devices

Mon, 06 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Improper Input Validation Allows Command Injection on UniFi OS Devices

Mon, 06 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title UniFi OS Command Injection via Improper Input Validation

Sun, 05 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title UniFi OS Command Injection via Improper Input Validation

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Command Injection in UniFi OS via Improper Input Validation

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Command Injection in UniFi OS via Improper Input Validation

Sat, 04 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title UniFi OS Improper Input Validation Leading to Remote Command Execution

Sat, 04 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title UniFi OS Improper Input Validation Leading to Remote Command Execution

Fri, 03 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Input Validation in UniFi OS

Fri, 03 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Command Injection via Improper Input Validation in UniFi OS

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-02T15:52:04.606Z

Reserved: 2026-06-13T15:00:00.604Z

Link: CVE-2026-54402

cve-icon Vulnrichment

Updated: 2026-07-02T15:41:32.941Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation