Description
A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
Published: 2026-09-22
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A malicious actor who can reach the local network can trigger an out‑of‑bounds write inside certain UniFi gateway devices. This flaw can cause the device to hang or reboot, effectively denying legitimate traffic and disrupting network services. The impact is confined to the affected device and its connected networks, with no known pathway for remote code execution.

Affected Systems

The vulnerability affects devices in Ubiquiti's product families including Cloud Gateways, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewalls, Express, Express 7, and UniFi Gateways. No specific model or firmware versions are listed, so all devices within these families are potentially impacted unless confirmed otherwise by the vendor.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact and high complexity for exploitation. The EPSS score is not provided, so the probability of exploitation cannot be precisely quantified at this time. The flaw is not listed in CISA's KEV catalog, suggesting no publicly known active exploits at the time of this report. Attackers would need network connectivity to the vulnerable device, typically via the wireless or wired interface, to send a crafted packet that triggers the out-of-bounds write and causes a DoS.

Generated by OpenCVE AI on September 22, 2026 at 19:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware or security patch released by Ubiquiti for the affected gateway devices
  • Restrict or block traffic to the vulnerable service or port on the gateway using a firewall or access control list
  • Monitor the gateway for unexpected reboots or restart loops and check logs for anomalous activity

Generated by OpenCVE AI on September 22, 2026 at 19:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in UniFi Gateways Leading to Device Denial of Service

Tue, 22 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-09-22T19:32:21.278Z

Reserved: 2026-08-20T20:32:37.793Z

Link: CVE-2026-77544

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-22T19:16:51.600

Modified: 2026-09-22T19:41:38.447

Link: CVE-2026-77544

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:30:14Z

Weaknesses