← Back

Ui

ui

87 CVEs • 246 products

Products (246)

Click to collapse
Toggle
Er X Firmware
er-x_firmware
Unifi Video
unifi_video
Unifi Protect
unifi_protect
Airos
airos
Desktop
desktop
Edgeswitch X
edgeswitch_x
Edgeos
edgeos
Er 4 Firmware
er-4_firmware
Aircam
aircam
Aircam Dome
aircam_dome
Aircam Mini
aircam_mini
Edgeswitch
edgeswitch
Ucrm
ucrm
Af5x Firmware
af5x_firmware
Af5 Firmware
af5_firmware
Unifi Firmware
unifi_firmware
Ep R6 Firmware
ep-r6_firmware
Er 8 Firmware
er-8_firmware
Ep R8 Firmware
ep-r8_firmware
Mfi Controller
mfi_controller
Cloud Key Gen2
cloud_key_gen2
Unifi Talk
unifi_talk
Af 2x Firmware
af-2x_firmware
Usg Firmware
usg_firmware
Unifi Os
unifi_os
Unifi Access
unifi_access
Ubb Firmware
ubb_firmware
Airmax Ac
airmax_ac
Airmax M Xm
airmax_m_xm
Airmax M Xw
airmax_m_xw
Airmax M Ti
airmax_m_ti
Airgateway
airgateway
Airfiber Af24
airfiber_af24
Af5x
af5x
Af5
af5
Airmax M
airmax_m
Edgeswitch Xp
edgeswitch_xp
Edgemax
edgemax
Erlite 3
erlite-3
Unifi 52
unifi_52
Ep S16.
ep-s16.
Es 12f
es-12f
Es 16 150w
es-16-150w
Es 16 Xg
es-16-xg

CVEs (87)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ui
1Unifi Video
Nov 21, 2024
Apr 1, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoints does not implement sufficient privilege checks. Low privileged users, belonging to the PUBLIC_GROU...Show more
The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoints does not implement sufficient privilege checks. Low privileged users, belonging to the PUBLIC_GROUP or CUSTOM_GROUP groups, can access these endpoints and overwrite the current application configuration. This can be abused for various purposes, including adding new administrative users. Affected Products: UniFi Video Controller v3.9.3 (for Windows 7/8/10 x64) and prior. Fixed in UniFi Video Controller v3.9.6 and newer.Show less
1Ui
1Unifi Video
Nov 21, 2024
Apr 1, 2020
N/A· v4
8.4 HIGH· v3
5.2 MEDIUM· v2
The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under certain circumstances, does not validate firmware download destinations to ensure they are within the in...Show more
The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under certain circumstances, does not validate firmware download destinations to ensure they are within the intended destination directory tree. It accepts a request with a URL to firmware update information. If the version field contains ..\ character sequences, the destination file path to save the firmware can be manipulated to be outside the intended destination directory tree. Fixed in UniFi Video Controller v3.10.3 and newer.Show less
1Ui
3Airvision Controller
Mfi ControllerUnifi Controller
Nov 21, 2024
Feb 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new admin...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new admin user via a request to api/add/admin; (2) have unspecified impact via a request to api/add/wlanconf; change the guest (3) password, (4) authentication method, or (5) restricted subnets via a request to api/set/setting/guest_access; (6) block, (7) unblock, or (8) reconnect users by MAC address via a request to api/cmd/stamgr; change the syslog (9) server or (10) port via a request to api/set/setting/rsyslogd; (11) have unspecified impact via a request to api/set/setting/smtp; change the syslog (12) server, (13) port, or (14) authentication settings via a request to api/cmd/cfgmgr; or (15) change the Unifi Controller name via a request to api/set/setting/identity.Show less
1Ui
1Edgeswitch
Nov 21, 2024
Feb 7, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resulting in local commands execution, allowing an operator user (Privilege-1) to escalate privileges and...Show more
A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resulting in local commands execution, allowing an operator user (Privilege-1) to escalate privileges and became administrator (Privilege-15).Show less
1Ui
1Unifi Video Controller
Nov 21, 2024
Nov 26, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A privilege escalation exists in UniFi Video Controller =<3.10.6 that would allow an attacker on the local machine to run arbitrary commands.
1Ui
12Ep R6 Firmware
Ep R8 FirmwareEr 12 Firmware+9 more
Nov 21, 2024
Sep 25, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in /var/run/beaker/container_file/ are created when providing a valid length payload of 2...Show more
Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in /var/run/beaker/container_file/ are created when providing a valid length payload of 249 characters or fewer to the beaker.session.id cookie in a GET header. The attacker can use a long series of unique session IDs.Show less
1Ui
1Unifi Controller
Nov 21, 2024
Jul 30, 2019
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record their SMTP credentials for malicious use later.
1Ui
1Edgeswitch Firmware
Nov 21, 2024
Jul 10, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root.
1Ui
1Edgeswitch Firmware
Nov 21, 2024
Jul 10, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
DoS in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to Crash the SSH CLI interface by using crafted commands.
1Ui
1Airos
Nov 5, 2025
Jun 11, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1...Show more
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected.Show less
1Ui
1Unifi Firmware
Nov 21, 2024
Jun 7, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free time" Wi-Fi usage by sending a /guest/s/default/ request to obtain a cookie, and then using this cooki...Show more
Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free time" Wi-Fi usage by sending a /guest/s/default/ request to obtain a cookie, and then using this cookie in a /guest/s/default/login request with the byfree parameter.Show less
1Ui
1Edgeos
Nov 21, 2024
Jun 7, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remote attackers to execute arbitrary code with admin credentials, because /opt/vyatta/share/vyatta-cfg/templates/system/static-host-mapping/host-name/node.def does...Show more
Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remote attackers to execute arbitrary code with admin credentials, because /opt/vyatta/share/vyatta-cfg/templates/system/static-host-mapping/host-name/node.def does not sanitize the 'alias' or 'ips' parameter for shell metacharacters.Show less
1Ui
1Aircam Firmware
Nov 21, 2024
Jun 4, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
On Ubiquiti airCam 3.1.4 devices, a Denial of Service vulnerability exists in the RTSP Service provided by the ubnt-streamer binary. The issue can be triggered via malformed RTSP requests that lead to an invalid memory r...Show more
On Ubiquiti airCam 3.1.4 devices, a Denial of Service vulnerability exists in the RTSP Service provided by the ubnt-streamer binary. The issue can be triggered via malformed RTSP requests that lead to an invalid memory read. To exploit the vulnerability, an attacker must craft an RTSP request with a large number of headers.Show less
1Ui
1Unifi Video
Nov 21, 2024
May 6, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes on the server configuration without the user consent, requiring the attacker to lure an authenticat...Show more
In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes on the server configuration without the user consent, requiring the attacker to lure an authenticated user to access on attacker controlled page.Show less
1Ui
1Edgeswitch X
Nov 21, 2024
Apr 10, 2019
N/A· v4
4.8 MEDIUM· v3
5.8 MEDIUM· v2
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dynamic port forwarding" (SOCKS proxy) functionalities. Remote attackers without credentials can exploi...Show more
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dynamic port forwarding" (SOCKS proxy) functionalities. Remote attackers without credentials can exploit this bug to access local services or forward traffic through the device if SSH is enabled in the system settings.Show less
1Ui
1Edgeswitch X
Nov 21, 2024
Apr 10, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the SSH interface bypassing the CLI interface, which allow them to escalate privileges to root.
1Ui
1Edgeswitch X
Nov 21, 2024
Apr 10, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH CLI interface. This allows to execute shell commands under the root user.
1Ui
2Airos
Edgemax Firmware
Nov 21, 2024
Feb 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attacks.
2Ubnt
Ui
12Af5 Firmware
Af5x FirmwareAirfiber Af24 Firmware+9 more
Nov 21, 2024
Sep 5, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques....Show more
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.Show less
1Ui
1Ucrm
Nov 21, 2024
Jul 3, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Ubiquiti UCRM versions 2.5.0 to 2.7.7 are vulnerable to Stored Cross-site Scripting. Due to the lack sanitization, it is possible to inject arbitrary HTML code by manipulating the uploaded filename. Successful exploitati...Show more
Ubiquiti UCRM versions 2.5.0 to 2.7.7 are vulnerable to Stored Cross-site Scripting. Due to the lack sanitization, it is possible to inject arbitrary HTML code by manipulating the uploaded filename. Successful exploitation requires valid credentials to an account with "Edit" access to "Scheduling".Show less