Impact
The vulnerability is a path traversal flaw (CWE‑22) that allows an attacker who can reach the UniFi OS device over the network to supply a malicious file path to the system. By exploiting this flaw, the attacker can bypass the device’s normal authentication checks, thereby gaining unauthorized access to the management interface. The description does not explicitly state which privileged actions become available, but based on the description it is inferred that bypassing authentication could enable the use of privileged functions.
Affected Systems
The flaw affects Ubiquiti Inc. devices running UniFi OS, including Cloud Gateways, Cloud Keys, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewall Core, Enterprise Fortress Gateway, Enterprise Video Recorders, Express 7, Network Attached Storage, Network Video Recorders, and UniFi OS Server. Specific firmware revisions that contain the issue are not disclosed in the advisory; users should verify that their device version is either the patched release or has the path‑traversal fix applied.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score of less than 1 % suggests the vulnerability is infrequently targeted. It is not listed in CISA KEV catalog. The vulnerability requires only network access to the UniFi OS device’s management interface; an attacker must be able to reach the device’s API or web interface to supply a path‑traversal request and bypass authentication.
OpenCVE Enrichment