Impact
A malicious actor with network access and a low-privileged account can exploit a group of authenticated SQL injection flaws in UniFi OS. By injecting crafted SQL statements, the attacker can manipulate the underlying database, gain elevated privileges and potentially reach full administrative control of the device. The flaw is classified as CWE-89, indicating improper handling of user-supplied SQL strings.
Affected Systems
The vulnerability affects Ubiquiti Inc hardware running UniFi OS, including Cloud Gateways, Cloud Keys, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewall Core, Enterprise Fortress Gateway, Enterprise Video Recorders, Express 7, Network Attached Storage, Network Video Recorders, and the UniFi OS Server. No specific firmware or package versions were identified in the advisory.
Risk and Exploitability
The CVSS score of 8.8 signals high severity, while the EPSS score of less than 1 % suggests that exploitation is currently unlikely in the wild. The flaw requires that the attacker already has access to the device’s management interface and is authenticated with a low-privilege account; once those conditions are met, the injection can be used to elevate privileges and seize control. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment