CVE-2026-21638
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: support@hackerone.com (Secondary)
Description
A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product.
Affected Products:
UBB-XG (Version 1.2.2 and earlier)
UDB-Pro/UDB-Pro-Sector (Version 1.4.1 and earlier)
UBB (Version 3.1.5 and earlier)
Mitigation:
Update your UBB-XG to Version 1.2.3 or later.
Update your UDB-Pro/UDB-Pro-Sector to Version 1.4.2 or later.
Update your UBB to Version 3.1.7 or later.
Affected (4)
Products: Ui: Ubb Xg Firmware, Udb Pro Firmware, Udb Pro Sector Firmware, Ubb Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.3 |
| Running on/with | Platform Versions |
|---|---|
Ui Ubb Xg | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.2 |
| Running on/with | Platform Versions |
|---|---|
Ui Udb Pro | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.2 |
| Running on/with | Platform Versions |
|---|---|
Ui Udb Pro Sector | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.1.7 |
| Running on/with | Platform Versions |
|---|---|
Ui Ubb | All versions |
References (1)
Source: support@hackerone.com
Vendor Advisory
Timeline
No history available yet.