Impact
The vulnerability is an uncontrolled recursion flaw that allows a malicious actor on the same network to trigger a denial‑of‑service condition on affected UniFi gateway devices. The flaw is triggered without authentication, and it can cause the device to become unresponsive or crash, disrupting network connectivity.
Affected Systems
This issue affects a range of Ubiquiti products, including Cloud Gateways, Dream Machines, Dream Routers, Dream Wall, Enterprise Firewalls, Express, Express 7, and UniFi Gateways. No specific firmware versions are listed, so all current and past releases of these devices should be examined for the fix.
Risk and Exploitability
The CVSS score of 7.5 marks this flaw as high severity, and although EPSS data is unavailable, the lack of innovative mitigation and the public acknowledgment by Ubiquiti place practical risk at a moderate to high level. The flaw can be exploited by any entity with network presence, making it a straightforward yet disruptive attack once the device is reachable.
OpenCVE Enrichment