ZeroHour

CVE-2026-77554

moderate1

Unauthenticated Command Injection in Ubiquiti UniFi Talk Application

CVSS 3.1
10.0 critical
EPSS
<1%p60
Published
()
Modified
AI analysis

Ubiquiti's UniFi Talk Application contains an improper input validation flaw (CWE-20) that can be leveraged for command injection on the host device. The bug is triggered when untrusted input reaches the application over the network; per the CVSS vector, an attacker needs network reachability but no credentials, privileges, or user interaction (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields command execution on the underlying Talk host with high impact to confidentiality, integrity, and availability and a scope change, earning the maximum CVSS 3.1 score of 10.0. Any organization running the UniFi Talk Application is affected; this is one of three 10.0-rated flaws patched across Ubiquiti's UniFi line, although the available data does not list specific affected or fixed versions. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates a 1% probability of exploitation within 30 days.

What to do: Update the UniFi Talk Application to the latest patched release published by Ubiquiti; the source data does not name the fixed version, so consult Ubiquiti's release notes for the patch released alongside the three 10.0-rated UniFi fixes. Restrict network access to the Talk Application to trusted management segments, since exploitation requires only network reachability with no authentication. Given the maximum-severity score and lack of public exploitation so far, prioritize patching internet-reachable deployments and monitor for emerging PoCs.

Affected
Ubiquiti UniFi Talk Application
Estimated exposure
moderatelikely low tens of thousands of deployments worldwide at most (no published install counts; niche product line) — Ubiquiti does not publish install counts for UniFi Talk, which is a niche VoIP product line with far smaller adoption than the core UniFi Network line and is typically deployed on-premises at small-to-midsize sites, supporting an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device.

Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

Three 10.0 security flaws fixed across Ubiquiti’s UniFi line

Ubiquiti patches 22 UniFi vulnerabilities, 21 rated critical including three CVSS 10.0 flaws enabling unauthorized access.

Ubiquiti disclosed and patched 22 vulnerabilities, 21 rated critical and three assigned the maximum CVSS 10.0 score: CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554. All three involve improper access control that could let attackers gain privileges, while other flaws permit authentication bypass or arbitrary command execution. All but one of the 22 affect the UniFi product line. The company did not confirm whether any were exploited before patching.