A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
An attacker with access to the network where UniFi Connect Application operates can exploit improper access control (CWE-284) to send a malicious request. The lack of appropriate authorization mechanisms allows for command injection of system commands, which are subsequently executed by the host device with elevated privileges. The attack does not require authentication or user interaction, and its scope extends beyond the application (Scope: Changed).
An attacker can gain full control over the host device, including reading confidential data, modifying system configuration, or causing system unavailability. It is also possible to use the compromised device for further lateral movement within the network.
Apply patches available from the manufacturer according to the references: https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc. It is also recommended to restrict network access to the UniFi Connect Application interface exclusively to trusted hosts using firewall or network segmentation until updates are deployed.
UniFi Connect Application — versions indicated in the manufacturer's references (Ubiquiti)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HUi Unifi Connect Application
APPUi< 3.24.20
Related vulnerabilities
Nieprawidłowa kontrola dostępu w UniFi OS — nieautoryzowane zmiany systemowe
Path Traversal w UniFi OS — dostęp do plików systemowych i przejęcie konta
Command Injection w UniFi OS via nieprawidłowa walidacja wejścia
Command injection w Ubiquiti AirOS via stainfo.cgi (ifname)
SQL Injection w UniFi Talk Application umożliwia eskalację uprawnień