Impact
An attacker with network access to a UniFi OS device can craft a request containing special CRLF sequences that the system fails to neutralize properly. This allows the attacker to bypass authentication and gain unauthorized control of the device or the underlying instance. The flaw is an instance of Improper Neutralization of CRLF Sequences (CWE-93) and can compromise device integrity and availability.
Affected Systems
Vulnerable devices include Ubiquiti Cloud Gateways, Cloud Keys, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewall Core, Enterprise Fortress Gateway, Enterprise Network Attached Storage, Enterprise Network Video Recorders, Express, Express 7, Network Attached Storage, Network Video Recorders, and UniFi OS Server. Version information is not presently available.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. Although the EPSS score is not available, the lack of a KEV listing does not diminish the potential impact of this flaw. The attack vector is inferred to be network-based; an attacker must be able to reach the UniFi OS management interface, likely from a local network segment. The vulnerability can be exploited remotely by sending a crafted HTTP request to the device’s authentication endpoint, leading to authentication bypass.
OpenCVE Enrichment