ZeroHour
Product

UniFi

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Three 10.0 security flaws fixed across Ubiquiti’s UniFi line

Ubiquiti patches 22 UniFi vulnerabilities, 21 rated critical including three CVSS 10.0 flaws enabling unauthorized access.

Ubiquiti disclosed and patched 22 vulnerabilities, 21 rated critical and three assigned the maximum CVSS 10.0 score: CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554. All three involve improper access control that could let attackers gain privileges, while other flaws permit authentication bypass or arbitrary command execution. All but one of the 22 affect the UniFi product line. The company did not confirm whether any were exploited before patching.

Weekly Update 518: IoT Doorlock Nirvana with UniFi

Troy Hunt describes building a home IoT door-lock setup around Ubiquiti UniFi hardware, relying on main power rather than batteries.

In Weekly Update 518, Troy Hunt describes integrating Ubiquiti UniFi smart door locks into his home, calling the result IoT door-lock nirvana. He highlights basic tenets such as powering the locks from main power rather than relying on batteries.

Troy Hunt · 22d agoOther

Related CVEs

  • Unauthenticated Command Injection in Ubiquiti UniFi Talk Application
    Ubiquiti's UniFi Talk Application contains an improper input validation flaw (CWE-20) that can be leveraged for command injection on the host device. The bug is triggered when untrusted input reaches the application over the network; per the CVSS vector, an attacker needs network reachability but no credentials, privileges, or user interaction (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields command execution on the underlying Talk host with high impact to confidentiality, integrity, and availability and a scope change, earning the maximum CVSS 3.1 score of 10.0. Any organization running the UniFi Talk Application is affected; this is one of three 10.0-rated flaws patched across Ubiquiti's UniFi line, although the available data does not list specific affected or fixed versions. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates a 1% probability of exploitation within 30 days.
    · Ubiquiti UniFi Talk Applicationmoderate
  • Authentication Bypass via CRLF Injection in Ubiquiti UniFi OS
    CVE-2026-77550 is an Improper Neutralization of CRLF (carriage return/line feed) sequences (CWE-93) in certain devices running Ubiquiti's UniFi OS, rated CVSS 10.0 with network reachability, no privileges, and no user interaction required. An attacker who can reach the vulnerable UniFi OS device or instance over the network sends crafted input containing CR/LF sequences, which disrupts authentication processing and lets the attacker bypass login entirely. Successful exploitation yields complete administrative control of the console or instance, with high impact on confidentiality, integrity, and availability, and the scope change in the CVSS vector indicates impact can extend beyond the vulnerable component to protected resources behind it. Any organization running an affected UniFi OS device is exposed, with the greatest risk for consoles or instances reachable from untrusted networks. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS puts near-term exploitation probability at about 0.5% (40th percentile); it is one of three 10.0-severity UniFi issues reported as fixed in recent updates.
    · Ubiquiti UniFi OS (certain devices/instances)mass
  • Command Injection in Ubiquiti UniFi Protect Application
    CVE-2026-77537 is an Improper Input Validation flaw (CWE-20) in Ubiquiti's UniFi Protect Application that allows a command injection against the host device. It is triggered by attacker-controlled input submitted over the network to the Protect application, and the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C) indicates no authentication, user interaction, or special conditions are required. A successful exploit yields code execution on the console hosting Protect, with critical confidentiality, integrity, and availability impact across the scope-changed host environment. Any organization or user running UniFi Protect — typically on a UniFi OS console that hosts the surveillance application — is potentially affected. There is no evidence of exploitation in the wild and no known public proof-of-concept; EPSS assigns a 0.9% probability of exploitation within 30 days, and vendor advisories report that fixes have shipped across the UniFi line.
    · Ubiquiti UniFi Protect Applicationlarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.