Impact
A malicious actor can lure an authenticated user to a malicious web page. The Cross‑Origin Resource Sharing policy in UniFi OS is overly permissive, causing the browser to automatically forward the victim’s authentication tokens with cross‑origin requests. This allows the attacker to invoke privileged API calls that the logged‑in user could normally perform, enabling unauthorized modifications, data exfiltration, or other privileged actions without compromising credentials.
Affected Systems
The flaw affects devices running UniFi OS, which includes Ubiquiti Inc products such as Cloud Gateways, Cloud Keys, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewall Core, Enterprise Fortress Gateway, Enterprise Video Recorders, Express 7, Network Attached Storage, Network Video Recorders and the UniFi OS Server. Affected version information is not specified, so administrators should verify whether their firmware or software includes the CORS fix.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of <1% suggests a low probability of real‑world exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is social engineering: a victim, while logged in to UniFi OS, visits a malicious site that triggers cross‑origin requests under the target’s session. No local privilege escalation is required; the attack depends on an authenticated user’s presence in a browser context.
OpenCVE Enrichment