ZeroHour

CVE-2026-54404

CVSS 3.1
8.8 high
EPSS
<1%p41
Published
()
Modified
Description

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances.

Vendors
ui
Products
unifi dream machine beast firmware, enterprise fortress gateway firmware, unifi dream router firmware, unifi dream wall firmware, unifi dream router 7 firmware, unifi express 7 firmware, unifi cloudkey firmware, unifi cloud key plus firmware, unifi cloudkey enterprise firmware, unifi network video recorder firmware, unifi network video recorder pro firmware, unifi network video recorder instant firmware
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.