Impact
A buffer overflow flaw exists in the DHCPv6 implementation of Ubiquiti EdgeMAX EdgeSwitch devices that can be triggered by a malicious actor with access to the adjacent network. Exploitation leads to remote code execution on the switch, compromising confidentiality, integrity, and availability of the device and potentially the entire network it serves. The weakness is classified as CWE‑122. This vulnerability carries a CVSS score of 9.6, indicating extremely high severity.
Affected Systems
The affected product is Ubiquiti EdgeMAX EdgeSwitch with DHCPv6 enabled. No specific firmware versions are listed as vulnerable, so all firmware that supports DHCPv6 on these devices should be considered at risk.
Risk and Exploitability
The attack vector is inferred to be an attacker positioned on a local or adjacent network segment that can communicate with the EdgeSwitch’s DHCPv6 service. Because a patch is not yet publicly available and the EPSS score is not provided, the exploitation risk remains high for environments that rely on DHCPv6. The vulnerability is not listed in the CISA KEV catalog, but the CVSS 9.6 score warrants immediate attention, especially in high‑risk networks.
OpenCVE Enrichment