Impact
The vulnerability is a flaw in input validation that permits an attacker with network reach and privileged access to inject and execute arbitrary commands on the UID Enterprise Agent host. Such a command injection could lead to complete compromise of the device, granting an attacker full control, data exfiltration, and potential pivot into the broader network. This weakness aligns with CWE‑20.
Affected Systems
The flaw affects Ubiquiti Inc's UID Enterprise Agent. No specific version numbers are disclosed in the advisory, so all installations should be assumed at risk until a vendor patch is applied.
Risk and Exploitability
The CVSS score of 9.1 classifies the issue as Critical, and while EPSS data is unavailable, the lack of mitigation in the KEV suggests it has not yet been widely exploited publicly. The attack vector is inferred to be network‑based with high privileges, meaning attackers with local network presence or compromised credentials can exploit it. The absence of a public exploit does not diminish the potential damage if accessed internally.
OpenCVE Enrichment