Ubiquiti UniFi: Multiple Vulnerabilities
A BSI Warn- und Informationsdienst (WID): Schwachstellen-Informationen (Bürger Cert) ·
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key insight
The BSI report summarises several vulnerabilities in Ubiquiti UniFi but provides no CVE IDs or affected versions, so the vendor advisories are needed for specifics.
Description
The report describes multiple vulnerabilities in Ubiquiti UniFi stemming from insufficient access control, SQL injection, missing input validation, server-side request forgery, path traversal, insufficient initialisation, a CORS misconfiguration and faulty authorisation. An attacker can thereby execute arbitrary code, carry out SQL injection attacks, escalate privileges, bypass security protections, cause a denial of service, manipulate data and disclose information. The report provides neither CVE IDs nor affected product versions and makes no statement about a public exploit or exploitation in the wild; the assessment as a vulnerability advisory without confirmation of active attacks therefore stands.
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 0.00
- industry weight
- 1.21
- freshness factor
- 0.50
- exploitability factor
- 1.00
- days old
- 71.00
- vendor mismatch penalty
- 0.00
Path: operational