Impact
A flaw that allows a malicious actor with access to the internal network and elevated privileges to inject arbitrary commands into the UniFi OS Server. The vulnerability is an improper validation of input that leads to command injection on the host device, effectively granting full control over the system. Such an execution path can compromise data confidentiality, integrity, and availability, and can be leveraged to propagate to other network assets.
Affected Systems
The affected product is the UniFi OS Server from Ubiquiti Inc. No specific version information is listed, so any installation of the server that has not been updated to the latest firmware may be vulnerable.
Risk and Exploitability
The CVSS score of 9.1 classifies this issue as Critical. The EPSS score is not available, but the vulnerability is not listed in CISA’s KEV catalog. A likely attack vector requires the attacker to be on the same internal network and to possess high-level privileges on the device or the ability to send crafted input to the server’s interfaces. Once exploited, the attacker could execute arbitrary commands with the privileges of the UniFi OS Server process.
OpenCVE Enrichment