AI analysis
CVE-2026-77550 is an Improper Neutralization of CRLF (carriage return/line feed) sequences (CWE-93) in certain devices running Ubiquiti's UniFi OS, rated CVSS 10.0 with network reachability, no privileges, and no user interaction required. An attacker who can reach the vulnerable UniFi OS device or instance over the network sends crafted input containing CR/LF sequences, which disrupts authentication processing and lets the attacker bypass login entirely. Successful exploitation yields complete administrative control of the console or instance, with high impact on confidentiality, integrity, and availability, and the scope change in the CVSS vector indicates impact can extend beyond the vulnerable component to protected resources behind it. Any organization running an affected UniFi OS device is exposed, with the greatest risk for consoles or instances reachable from untrusted networks. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS puts near-term exploitation probability at about 0.5% (40th percentile); it is one of three 10.0-severity UniFi issues reported as fixed in recent updates.
What to do: Apply the latest UniFi OS firmware/update release from Ubiquiti, which includes the fixes for this and the other two 10.0 flaws in the same advisory batch. Until patched, restrict network access to UniFi OS management interfaces (e.g., firewall rules or VPN-only access) and avoid exposing consoles directly to the internet. Check internet-facing UniFi OS instances for exposure and monitor for vendor advisories identifying specific affected/fixed versions.
Affected
| Ubiquiti UniFi OS (certain devices/instances) | — |
Estimated exposure
massmillions of installed UniFi devices, with on the order of 100,000+ consoles/instances likely internet-exposed — Ubiquiti's UniFi line has a multi-million-device installed base per vendor deployment figures, and public internet scans (Shodan/Censys) index roughly 100,000+ exposed UniFi OS controllers/instances; exact affected-version coverage is not…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.