Impact
A malicious actor who can reach the local network can trigger an out‑of‑bounds write inside certain UniFi gateway devices. This flaw can cause the device to hang or reboot, effectively denying legitimate traffic and disrupting network services. The impact is confined to the affected device and its connected networks, with no known pathway for remote code execution.
Affected Systems
The vulnerability affects devices in Ubiquiti's product families including Cloud Gateways, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewalls, Express, Express 7, and UniFi Gateways. No specific model or firmware versions are listed, so all devices within these families are potentially impacted unless confirmed otherwise by the vendor.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact and high complexity for exploitation. The EPSS score is not provided, so the probability of exploitation cannot be precisely quantified at this time. The flaw is not listed in CISA's KEV catalog, suggesting no publicly known active exploits at the time of this report. Attackers would need network connectivity to the vulnerable device, typically via the wireless or wired interface, to send a crafted packet that triggers the out-of-bounds write and causes a DoS.
OpenCVE Enrichment