Impact
A vulnerability in UniFi OS Server allows an attacker with network access and elevated privileges to inject and execute arbitrary commands on the host device. The flaw is caused by improper input validation, making it a classic command injection scenario that can compromise the entire infrastructure managed by the server.
Affected Systems
The affected product is Ubiquiti Inc’s UniFi OS Server. Specific version numbers are not reported in the advisory, so all installations of UniFi OS Server may be vulnerable unless they are already patched to the latest release.
Risk and Exploitability
The CVSS score of 9.1 classifies the issue as critical, reflecting the potential for full system compromise. The EPSS score is unavailable, so the current probability of exploitation is unknown, but the lack of a KEV listing does not diminish the need for rapid remediation. Attacks require the adversary to be on the same network segment and to possess high‑privilege credentials on the server—a condition that many administrators and support staff meet, thereby creating a realistic threat vector.
OpenCVE Enrichment