Impact
A malicious actor with network presence could exploit an improper input validation flaw in the UniFi Talk Application, leading to command injection that allows execution of arbitrary commands on the host device. The flaw permits injection of system commands through crafted network traffic, potentially giving the attacker full control over the device and any systems it connects to. The vulnerability’s severity is reflected in a CVSS score of 10, indicating a critical impact on confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects the UniFi Talk Application from Ubiquiti Inc. No specific affected versions are listed in the advisory, so any deployed instance of UniFi Talk should be considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 10 categorizes this flaw as critical, and while the EPSS score is not available, its absence in the CISA KEV catalog does not diminish its potential for exploitation. The attacker requires only network access to the target device, making the attack vector relatively low effort and high potential reward. Successful exploitation could lead to full system compromise, command execution, data exfiltration, and service disruption.
OpenCVE Enrichment