Impact
The flaw is caused by Improper Input Validation in UniFi Protect Application, permitting a malicious actor who can reach the device on the local network to inject arbitrary shell commands. Such injection would allow full control of the host, compromising confidentiality, integrity, and availability of the device and potentially any services linked to it.
Affected Systems
All installations of Ubiquiti Inc.'s UniFi Protect Application are potentially affected; the advisory does not specify version ranges. Any device running the Protect application on a network with exposed interfaces can be vulnerable.
Risk and Exploitability
With a CVSS score of 10, the vulnerability is classified as critical. The EPSS score is not provided, so exploitation probability is unknown, but the absence of any published public exploits and lack of a KEV listing suggests the threat is not yet exploited in the wild. The likely attack vector requires network access, meaning devices in unsegmented or poorly protected environments are at higher risk.
OpenCVE Enrichment