A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
An attacker with access to the network in which UniFi OS devices operate can send specially crafted input data to the vulnerable system component. Due to the lack of proper validation of this data, malicious data is interpreted as system commands and executed by the device. The vulnerability is remotely exploitable without the need for privileges or user engagement.
Successful exploitation of this vulnerability allows an attacker to remotely execute arbitrary system commands on the device (command injection), which may lead to complete takeover of the device, loss of confidentiality and integrity of data, and disruption of service availability.
Apply patches available from the manufacturer in accordance with the references. Detailed information about versions containing fixes is available in the Ubiquiti security bulletin at the address indicated in the references section.
Devices running UniFi OS — versions indicated in the manufacturer's references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HUi Enterprise Fortress Gateway
HWUiall versionsUi Enterprise Fortress Gateway Firmware
OSUi< 5.1.12Ui Enterprise Network Video Recorder
HWUiall versionsUi Enterprise Network Video Recorder Core
HWUiall versionsUi Enterprise Network Video Recorder Core Firmware
OSUi< 5.1.12Ui Enterprise Network Video Recorder Firmware
OSUi< 5.1.12Ui Unas 2
HWUiall versionsUi Unas 2 Firmware
OSUi< 5.1.10Ui Unas 4
HWUiall versionsUi Unas 4 Firmware
OSUi< 5.1.10Ui Unas Pro
HWUiall versionsUi Unas Pro 4
HWUiall versionsUi Unas Pro 4 Firmware
OSUi< 5.1.10Ui Unas Pro 8
HWUiall versionsUi Unas Pro 8 Firmware
OSUi< 5.1.10Ui Unas Pro Firmware
OSUi< 5.1.10Ui Unifi Cloud Gateway Fiber
HWUiall versionsUi Unifi Cloud Gateway Fiber Firmware
OSUi< 5.1.12Ui Unifi Cloud Gateway Industrial
HWUiall versionsUi Unifi Cloud Gateway Industrial Firmware
OSUi< 5.1.12Ui Unifi Cloud Gateway Max
HWUiall versionsUi Unifi Cloud Gateway Max Firmware
OSUi< 5.1.12Ui Unifi Cloud Gateway Ultra
HWUiall versionsUi Unifi Cloud Gateway Ultra Firmware
OSUi< 5.1.12Ui Unifi Cloudkey
HWUiall versionsUi Unifi Cloudkey Enterprise
HWUiall versionsUi Unifi Cloudkey Enterprise Firmware
OSUi< 5.1.12Ui Unifi Cloudkey Firmware
OSUi< 5.1.12Ui Unifi Cloud Key Plus
HWUiall versionsUi Unifi Cloud Key Plus Firmware
OSUi< 5.1.12
CISA KEV — detailsi
- Vendori
- Ubiquiti
- Producti
- UniFi OS
- Added to KEVi
- June 23, 2026
- Remediation deadline (US Federal)i
- June 26, 2026(overdue)
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
Related vulnerabilities
Path Traversal w UniFi OS — dostęp do plików systemowych i przejęcie konta
Nieprawidłowa kontrola dostępu w UniFi OS — nieautoryzowane zmiany systemowe
Command Injection w UniFi OS przez błąd walidacji wejścia
Command Injection w UniFi OS — podatność na wstrzyknięcie poleceń
Ubiquiti UniFi Dream Machine Pro — obejście restrykcji domenowych