A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
An attacker with a low-privilege account in the network can pass maliciously crafted input data to a vulnerable UniFi OS component, which does not perform proper validation. Lack of appropriate filtering allows for the injection of system commands (command injection), which are then executed by the host operating system. The network vector (AV:N) and lack of user interaction requirements (UI:N) mean that the attack can be conducted remotely and fully automated.
Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands on the host device, which may lead to complete device takeover, loss of data confidentiality and integrity, and disruption of its availability.
Patches available from the manufacturer should be applied in accordance with references published in Security Advisory Bulletin 066 at: https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc
Devices running Ubiquiti's UniFi OS — specific versions indicated in manufacturer references
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HUi Enterprise Firewall Core
HWUiall versionsUi Enterprise Firewall Core Firmware
OSUi≤ 5.1.18Ui Enterprise Fortress Gateway
HWUiall versionsUi Enterprise Fortress Gateway Firmware
OSUi≤ 5.1.15Ui Enterprise Network Video Recorder
HWUiall versionsUi Enterprise Network Video Recorder Core
HWUiall versionsUi Enterprise Network Video Recorder Core Firmware
OSUi≤ 5.1.15Ui Enterprise Network Video Recorder Firmware
OSUi≤ 5.1.15Ui Unas 2
HWUiall versionsUi Unas 2 Firmware
OSUi≤ 5.1.16Ui Unas 4
HWUiall versionsUi Unas 4 Firmware
OSUi≤ 5.1.16Ui Unas Pro
HWUiall versionsUi Unas Pro 4
HWUiall versionsUi Unas Pro 4 Firmware
OSUi≤ 5.1.16Ui Unas Pro 8
HWUiall versionsUi Unas Pro 8 Firmware
OSUi≤ 5.1.16Ui Unas Pro Firmware
OSUi≤ 5.1.16Ui Unifi Cloud Gateway Fiber
HWUiall versionsUi Unifi Cloud Gateway Fiber Firmware
OSUi≤ 5.1.15Ui Unifi Cloud Gateway Industrial
HWUiall versionsUi Unifi Cloud Gateway Industrial Firmware
OSUi≤ 5.1.15Ui Unifi Cloud Gateway Max
HWUiall versionsUi Unifi Cloud Gateway Max Firmware
OSUi≤ 5.1.15Ui Unifi Cloud Gateway Ultra
HWUiall versionsUi Unifi Cloud Gateway Ultra Firmware
OSUi≤ 5.1.15Ui Unifi Cloudkey
HWUiall versionsUi Unifi Cloudkey Enterprise
HWUiall versionsUi Unifi Cloudkey Enterprise Firmware
OSUi≤ 5.1.15Ui Unifi Cloudkey Firmware
OSUi≤ 5.1.15
Related vulnerabilities
Path Traversal w UniFi OS — dostęp do plików systemowych i przejęcie konta
Command Injection w UniFi OS via nieprawidłowa walidacja wejścia
Nieprawidłowa kontrola dostępu w UniFi OS — nieautoryzowane zmiany systemowe
Command Injection w UniFi OS — podatność na wstrzyknięcie poleceń
Ubiquiti UniFi Dream Machine Pro — obejście restrykcji domenowych