Impact
An Improper Input Validation flaw in the UniFi Protect Application allows an attacker who has network access and only low privileges on the host to inject and execute arbitrary system commands. The vulnerability can result in full control of the device, enabling the attacker to exfiltrate data, deploy malware, or pivot to other hosts on the network, compromising confidentiality, integrity, and availability of the protected video surveillance infrastructure.
Affected Systems
The flaw affects Ubiquiti Inc's UniFi Protect Application. The CVE report does not specify particular versions, so any deployment of this application that has not been patched by the vendor is potentially susceptible.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.9, indicating critical severity. Although the EPSS score is not available, the lack of a KEV listing does not diminish the inherent risk posed by the high CVSS. Attackers would need only local network connectivity and basic user privileges, which are commonly available on many deploy environments. Given the high CVSS, the potential for exploitation is high, and organizations should treat this as a top‑priority risk.
OpenCVE Enrichment