Description
A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
Published: 2026-09-22
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an uncontrolled recursion flaw that allows a malicious actor on the same network to trigger a denial‑of‑service condition on affected UniFi gateway devices. The flaw is triggered without authentication, and it can cause the device to become unresponsive or crash, disrupting network connectivity.

Affected Systems

This issue affects a range of Ubiquiti products, including Cloud Gateways, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewalls, Express, Express 7, and UniFi Gateways. No specific firmware versions are listed, so all current and past releases of these devices should be examined for the fix.

Risk and Exploitability

The CVSS score of 7.5 marks this flaw as high severity, and although EPSS data is unavailable, the lack of innovative mitigation and the public acknowledgment by Ubiquiti place practical risk at a moderate to high level. The flaw can be exploited by any entity with network presence, making it a straightforward yet disruptive attack once the device is reachable.

Generated by OpenCVE AI on September 22, 2026 at 20:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by Ubiquiti in Security‑Advisory‑Bulletin‑069-069, which addresses the uncontrolled recursion flaw.
  • If immediate firmware update is not possible, segment the device from general network traffic using firewall rules or VLAN isolation to limit exposure.
  • Monitor device performance and logs for repeated denial‑of‑service symptoms or high CPU usage, and disconnect the device if signs of exploitation appear.

Generated by OpenCVE AI on September 22, 2026 at 20:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Uncontrolled Recursion in UniFi Gateway Devices Enabling DoS

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ubiquiti

Published:

Updated: 2026-09-22T19:34:16.989Z

Reserved: 2026-09-22T16:47:06.490Z

Link: CVE-2026-95861

cve-icon Vulnrichment

Updated: 2026-09-22T19:34:11.736Z

cve-icon NVD

Status : Deferred

Published: 2026-09-22T19:17:00.353

Modified: 2026-09-22T20:17:13.467

Link: CVE-2026-95861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:00:16Z

Weaknesses