Impact
An improperly validated input field in the UniFi Access Application permits a low‑privilege attacker with network access to inject arbitrary shell commands onto the host device, potentially compromising confidentiality, integrity, and availability. The vulnerability maps to CWE‑20 — Input Validation. Because the injection runs directly on the host, a successful exploitation could lead to unrestricted command execution with the privileges of the application process, allowing a broad range of post‑exploitation actions.
Affected Systems
The weakness exists in Ubiquiti Inc’s UniFi Access Application. All releases of the application are affected, as specific version details are not provided in the advisory.
Risk and Exploitability
The CVSS base score of 9.9 places the flaw in the Critical range, indicating a high likelihood of severe impact. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog at this time. Attackers would need unauthenticated or low‑privileged network access to the UniFi Access Application; the vulnerability can be leveraged by sending crafted input that bypasses normal validation to inject shell commands, executing them on the host system.
OpenCVE Enrichment