Impact
A vulnerable input validation flaw in UniFi Enterprise Audio/Video Bridge allows an attacker to inject arbitrary shell commands. The flaw is a classic example of CWE-20, leading to untrusted data being passed to the operating system without proper sanitization. If an attacker succeeds, they can execute any command with the privileges of the bridge process, compromising device integrity and potentially the entire local network.
Affected Systems
The vulnerability affects Ubiquiti Inc’s UniFi Enterprise Audio/Video Bridge hardware. No specific firmware or version information is disclosed, so any device model using the affected Bridge firmware and exposed to the local network is potentially impacted. The device typically operates behind local routers but is reachable by any host on the internal network that can reach the bridge IP address.
Risk and Exploitability
The assigned CVSS score is 9.8, indicating a critical severity. EPSS data is not available, so the current likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog, but its critical SCORE and the required network access suggest that a determined attacker with local network privileges could easily abuse it. The likely attack vector is a local network attack, requiring an attacker to be on the same segment as the bridge.
OpenCVE Enrichment