Impact
The vulnerability is an Improper Neutralization of CRLF sequences that allows an attacker to craft HTTP request headers containing CRLF injects. When processed by the UniFi OS authentication component, these malformed sequences can be used to bypass credentials and gain unauthorized access to the device's management interface. This results in loss of confidentiality and integrity of configuration and device state, and provides a foothold for further exploitation within the network.
Affected Systems
The affected products are Ubiquiti Inc devices running UniFi OS, including Cloud Gateways, Cloud Keys, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewall Core, Enterprise Fortress Gateway, Enterprise Network Attached Storage, Enterprise Network Video Recorders, Express, Express 7, Network Attached Storage, Network Video Recorders, and the UniFi OS Server. Specific version details are not provided in the advisory.
Risk and Exploitability
The CVSS score of 9 indicates a high severity vulnerability. The EPSS score is not available, so the exact exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local network connection; an attacker with network access must be able to send crafted HTTP requests to an affected UniFi OS device to exploit the weakness. The potential impact is high, as bypassing authentication can lead to full administrative control of the device.
OpenCVE Enrichment