Impact
The vulnerability is an Improper Input Validation flaw that permits a malicious actor with network-level access and minimal privileges to inject and execute arbitrary system commands on the host running the UniFi Access Application. This allows the attacker to execute code with the privileges of the host service, potentially compromising confidentiality, integrity, and availability of the device.
Affected Systems
Affected systems are the UniFi Access Application provided by Ubiquiti Inc. No specific version information is supplied in the CVE data.
Risk and Exploitability
The CVSS score of 9.9 marks it as critical; the lack of an EPSS score does not indicate low risk, and it is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local network attacker with low privileges, who can send crafted inputs to trigger command execution. Remediation is urgent until a vendor patch becomes available.
OpenCVE Enrichment