Impact
The UniFi Protect Application contains an improper input validation flaw that allows a network actor with low privileges to inject arbitrary commands into the host system. By sending specially crafted input, an attacker can trigger command execution on the device, compromising the confidentiality, integrity, and availability of the system. This represents a classic command injection vulnerability (CWE‑20).
Affected Systems
All versions of Ubiquiti Inc's UniFi Protect Application that do not contain the vendor’s recent patch are affected. No specific version numbers are disclosed in the advisory, so administrators should assume all existing deployments are vulnerable until a fix is applied.
Risk and Exploitability
The severity is CVSS 9.9, indicating a critical risk. Although the EPSS score is not available and the vulnerability is not listed in CISA KEV, the requirement for only network access and low privileges means that internal attackers can easily exploit it. The resulting command injection grants full control over the host device, making this a high‑impact, high‑likelihood threat if left unmitigated.
OpenCVE Enrichment