AI analysis
Ubiquiti's UniFi Talk Application contains an improper input validation flaw (CWE-20) that can be leveraged for command injection on the host device. The bug is triggered when untrusted input reaches the application over the network; per the CVSS vector, an attacker needs network reachability but no credentials, privileges, or user interaction (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields command execution on the underlying Talk host with high impact to confidentiality, integrity, and availability and a scope change, earning the maximum CVSS 3.1 score of 10.0. Any organization running the UniFi Talk Application is affected; this is one of three 10.0-rated flaws patched across Ubiquiti's UniFi line, although the available data does not list specific affected or fixed versions. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates a 1% probability of exploitation within 30 days.
What to do: Update the UniFi Talk Application to the latest patched release published by Ubiquiti; the source data does not name the fixed version, so consult Ubiquiti's release notes for the patch released alongside the three 10.0-rated UniFi fixes. Restrict network access to the Talk Application to trusted management segments, since exploitation requires only network reachability with no authentication. Given the maximum-severity score and lack of public exploitation so far, prioritize patching internet-reachable deployments and monitor for emerging PoCs.
Affected
| Ubiquiti UniFi Talk Application | — |
Estimated exposure
moderatelikely low tens of thousands of deployments worldwide at most (no published install counts; niche product line) — Ubiquiti does not publish install counts for UniFi Talk, which is a niche VoIP product line with far smaller adoption than the core UniFi Network line and is typically deployed on-premises at small-to-midsize sites, supporting an…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.