Impact
A malicious actor who can reach the network and has low privileges can exploit an improper input validation flaw in UniFi Access Application to run arbitrary system commands on the host device. This allows the attacker to read, modify or delete data, install software, and potentially pivot to other systems in the network. The vulnerability is a classic command injection that compromises confidentiality, integrity and availability of the affected device.
Affected Systems
All installations of Ubiquiti’s UniFi Access Application are vulnerable until an official patch is applied. No specific version information is provided, so the risk applies to every current and legacy release until mitigated.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical risk level, and the vulnerability is not currently listed in CISA’s KEV catalog. The EPSS score is not available, but the lack of listed exploitation suggests no widespread public exploitation yet. Attackers would need to have network access and low privileges; the vulnerability can be triggered remotely over the network once an attacker can interact with the application’s input interfaces.
OpenCVE Enrichment