Impact
The vulnerability is an Improper Input Validation flaw that lets an attacker with network-level access send malformed data to the UniFi Network Application, causing the controller to crash or become unresponsive. The resulting denial of service affects only the availability of the network management interface, with no indication of confidentiality or integrity compromise.
Affected Systems
The flaw affects the UniFi Network Application from Ubiquiti Inc. No specific version information is provided, so the issue is presumed to apply to all current releases until a vendor patch is available.
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as high severity, while an EPSS score of <1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need network-level access to reach the controller, from which they could repeatedly send crafted requests to trigger the DoS.
OpenCVE Enrichment