Impact
A flaw in input validation within the UniFi Network Application permits a malicious actor who has network access and high privileges to inject and execute arbitrary commands on a device that has been adopted by the controller. The vulnerability enables remote command injection, allowing the attacker to run code with the privileges of the targeted device.
Affected Systems
All installations of Ubiquiti’s UniFi Network Application that have adopted devices are potentially vulnerable. No specific product version is identified, so any deployed instance may be affected until a patch or update is applied.
Risk and Exploitability
The CVSS score of 9.1 indicates a very high severity issue. EPSS data is not available and the vulnerability is not listed in CISA's KEV catalog, implying no known widespread exploitation yet. However, the required conditions—network access and elevated privileges—are common in many managed network environments, making the risk high and warranting immediate attention.
OpenCVE Enrichment