CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-54402

CVSS 9.9v3.1pub. 2026-07-02upd. 2026-07-10

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.

🤖 AI Analysis
How it works

An attacker with a low-privilege account in the network can pass maliciously crafted input data to a vulnerable UniFi OS component, which does not perform proper validation. Lack of appropriate filtering allows for the injection of system commands (command injection), which are then executed by the host operating system. The network vector (AV:N) and lack of user interaction requirements (UI:N) mean that the attack can be conducted remotely and fully automated.

Impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands on the host device, which may lead to complete device takeover, loss of data confidentiality and integrity, and disruption of its availability.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with references published in Security Advisory Bulletin 066 at: https://community.ui.com/releases/Security-Advisory-Bulletin-066-066/984eceb3-49c8-4227-942d-671c289b3afc

Who is affected

Devices running Ubiquiti's UniFi OS — specific versions indicated in manufacturer references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Ui Enterprise Firewall Core

    HW
    Ui
    all versions
  • Ui Enterprise Firewall Core Firmware

    OS
    Ui
    ≤ 5.1.18
  • Ui Enterprise Fortress Gateway

    HW
    Ui
    all versions
  • Ui Enterprise Fortress Gateway Firmware

    OS
    Ui
    ≤ 5.1.15
  • Ui Enterprise Network Video Recorder

    HW
    Ui
    all versions
  • Ui Enterprise Network Video Recorder Core

    HW
    Ui
    all versions
  • Ui Enterprise Network Video Recorder Core Firmware

    OS
    Ui
    ≤ 5.1.15
  • Ui Enterprise Network Video Recorder Firmware

    OS
    Ui
    ≤ 5.1.15
  • Ui Unas 2

    HW
    Ui
    all versions
  • Ui Unas 2 Firmware

    OS
    Ui
    ≤ 5.1.16
  • Ui Unas 4

    HW
    Ui
    all versions
  • Ui Unas 4 Firmware

    OS
    Ui
    ≤ 5.1.16
  • Ui Unas Pro

    HW
    Ui
    all versions
  • Ui Unas Pro 4

    HW
    Ui
    all versions
  • Ui Unas Pro 4 Firmware

    OS
    Ui
    ≤ 5.1.16
  • Ui Unas Pro 8

    HW
    Ui
    all versions
  • Ui Unas Pro 8 Firmware

    OS
    Ui
    ≤ 5.1.16
  • Ui Unas Pro Firmware

    OS
    Ui
    ≤ 5.1.16
  • Ui Unifi Cloud Gateway Fiber

    HW
    Ui
    all versions
  • Ui Unifi Cloud Gateway Fiber Firmware

    OS
    Ui
    ≤ 5.1.15
  • Ui Unifi Cloud Gateway Industrial

    HW
    Ui
    all versions
  • Ui Unifi Cloud Gateway Industrial Firmware

    OS
    Ui
    ≤ 5.1.15
  • Ui Unifi Cloud Gateway Max

    HW
    Ui
    all versions
  • Ui Unifi Cloud Gateway Max Firmware

    OS
    Ui
    ≤ 5.1.15
  • Ui Unifi Cloud Gateway Ultra

    HW
    Ui
    all versions
  • Ui Unifi Cloud Gateway Ultra Firmware

    OS
    Ui
    ≤ 5.1.15
  • Ui Unifi Cloudkey

    HW
    Ui
    all versions
  • Ui Unifi Cloudkey Enterprise

    HW
    Ui
    all versions
  • Ui Unifi Cloudkey Enterprise Firmware

    OS
    Ui
    ≤ 5.1.15
  • Ui Unifi Cloudkey Firmware

    OS
    Ui
    ≤ 5.1.15
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-34909CRITICAL10.0⚠ KEVPL ✓same product

Path Traversal w UniFi OS — dostęp do plików systemowych i przejęcie konta

CVE-2026-34910CRITICAL10.0⚠ KEVPL ✓same product

Command Injection w UniFi OS via nieprawidłowa walidacja wejścia

CVE-2026-34908CRITICAL10.0⚠ KEVPL ✓same product

Nieprawidłowa kontrola dostępu w UniFi OS — nieautoryzowane zmiany systemowe

CVE-2026-33000CRITICAL9.1PL ✓same product

Command Injection w UniFi OS — podatność na wstrzyknięcie poleceń

CVE-2023-24104CRITICAL9.8PL ✓same product

Ubiquiti UniFi Dream Machine Pro — obejście restrykcji domenowych