A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
An attacker with network access and high system privileges can deliver improperly validated input data to the vulnerable UniFi OS component. Lack of proper input validation (CWE-20) allows embedding malicious system commands in the input data, which are then executed by the device. Network attack vector (AV:N) and lack of user interaction requirement (UI:N) mean that the exploit can be performed remotely and fully automatically.
Successful exploitation of the vulnerability gives an attacker the ability to remotely execute arbitrary system commands on the device (RCE), which can lead to complete takeover of the device, breach of confidentiality and integrity of data, and denial of service (C:H/I:H/A:H). The scope of impact includes resources beyond the component itself (S:C), which increases the risk of lateral movement in the network.
Apply patches available from the manufacturer according to the references — details regarding fixed versions of UniFi OS software are contained in the security bulletin available at: https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b
Devices running UniFi OS — specific versions indicated in the manufacturer's references (Ubiquiti Security Advisory Bulletin 064)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HUi Unifi Os Server
APPUi< 5.0.8
Related vulnerabilities
Path Traversal w UniFi OS — dostęp do plików systemowych i przejęcie konta
Command Injection w UniFi OS via nieprawidłowa walidacja wejścia
Nieprawidłowa kontrola dostępu w UniFi OS — nieautoryzowane zmiany systemowe
Command Injection w UniFi OS przez błąd walidacji wejścia
Błędna konfiguracja CORS w UniFi OS umożliwia przejęcie sesji użytkownika