← Back

Ui

ui

118 CVEs • 310 products

Products (310)

Click to collapse
Toggle
Unifi Protect
unifi_protect
Er X Firmware
er-x_firmware
Unifi Video
unifi_video
Airos
airos
Desktop
desktop
Edgeswitch X
edgeswitch_x
Edgeos
edgeos
Er 4 Firmware
er-4_firmware
Aircam
aircam
Aircam Dome
aircam_dome
Aircam Mini
aircam_mini
Edgeswitch
edgeswitch
Ucrm
ucrm
Af5x Firmware
af5x_firmware
Af5 Firmware
af5_firmware
Unifi Firmware
unifi_firmware
Ep R6 Firmware
ep-r6_firmware
Er 8 Firmware
er-8_firmware
Ep R8 Firmware
ep-r8_firmware
Mfi Controller
mfi_controller
Cloud Key Gen2
cloud_key_gen2
Unifi Talk
unifi_talk
Af 2x Firmware
af-2x_firmware

CVEs (118)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ui
1Af 2x Firmware
Jun 17, 2026
Feb 2, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes Ubiquiti airFiber AF2X Radio firmware version 3.2.2 and earlier vulnerable to firmware modification attacks. An atta...Show more
The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes Ubiquiti airFiber AF2X Radio firmware version 3.2.2 and earlier vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification.Show less
1Ui
6Airfiber 60 Hd Firmware
Airfiber 60 Lr FirmwareAirfiber 60 Xg Firmware+3 more
Jun 17, 2026
Dec 23, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the U...Show more
An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the UISP device.Show less
1Ui
1Edgemax Edgerouter Firmware
Jun 17, 2026
Dec 5, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with an operator account to run arbitrary administrator commands.This vulnerability is fixed in Version 2...Show more
A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with an operator account to run arbitrary administrator commands.This vulnerability is fixed in Version 2.0.9-hotfix.5 and later.Show less
1Ui
1Desktop
Jun 17, 2026
Sep 23, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A local privilege escalation vulnerability in UI Desktop for Windows (Version 0.55.1.2 and earlier) allows a malicious actor with local access to a Windows device with UI Desktop to run arbitrary commands as SYSTEM.
1Ui
1Ua Lite Firmware
Jun 17, 2026
Apr 1, 2022
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a malicious actor who has gained access to a network to control all connected UA devi...Show more
A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a malicious actor who has gained access to a network to control all connected UA devices. This vulnerability is fixed in Version 3.8.31.13 and later.Show less
1Ui
1Unifi Network Controller
Jun 17, 2026
Jan 14, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a malicious actor to control the application.
1Ui
1Unifi Switch Firmware
Jun 17, 2026
Dec 7, 2021
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
A vulnerability found in UniFi Switch firmware Version 5.43.35 and earlier allows a malicious actor who has already gained access to the network to perform a Deny of Service (DoS) attack on the affected switch.This vulne...Show more
A vulnerability found in UniFi Switch firmware Version 5.43.35 and earlier allows a malicious actor who has already gained access to the network to perform a Deny of Service (DoS) attack on the affected switch.This vulnerability is fixed in UniFi Switch firmware 5.76.6 and later.Show less
1Ui
1Unifi Protect
Jun 17, 2026
Nov 24, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take...Show more
A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s account.This vulnerability is fixed in UniFi Protect application Version 1.20.0 and later.Show less
1Ui
1Unifi Talk
Jun 17, 2026
Sep 23, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequently control Talk device(s) assigned to said network if they are not yet...Show more
A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequently control Talk device(s) assigned to said network if they are not yet adopted. This vulnerability is fixed in UniFi Talk application V1.12.5 and later.Show less
1Ui
1Unifi Protect
Jun 17, 2026
Aug 31, 2021
N/A· v4
8.0 HIGH· v3
7.7 HIGH· v2
A vulnerability found in UniFi Protect application V1.18.1 and earlier allows a malicious actor with a view-only role and network access to gain the same privileges as the owner of the UniFi Protect application. This vul...Show more
A vulnerability found in UniFi Protect application V1.18.1 and earlier allows a malicious actor with a view-only role and network access to gain the same privileges as the owner of the UniFi Protect application. This vulnerability is fixed in UniFi Protect application V1.19.0 and later.Show less
1Ui
1Unifi Protect
Jun 17, 2026
Aug 31, 2021
N/A· v4
9.6 CRITICAL· v3
8.3 HIGH· v2
A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network to subsequently control the Protect camera(s) assigned to said network. This vul...Show more
A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network to subsequently control the Protect camera(s) assigned to said network. This vulnerability is fixed in UniFi Protect application V1.19.0 and later.Show less
1Ui
1Camera G3 Flex Firmware
Jun 17, 2026
Jun 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67.Attacker could send a huge amount of TCP SYN packet to make web service's resource exhausted. Then the web server is denial-of-service.
1Ui
1Camera G3 Flex Firmware
Jun 17, 2026
Jun 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the conne...Show more
An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.Show less
1Ui
1Edgemax Edgerouter Firmware
Jun 17, 2026
May 27, 2021
N/A· v4
7.5 HIGH· v3
7.6 HIGH· v2
A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-middle (MitM) attack during a firmware update. This vulnerability is fixed in EdgeMAX EdgeRouter V2.0.9...Show more
A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-middle (MitM) attack during a firmware update. This vulnerability is fixed in EdgeMAX EdgeRouter V2.0.9-hotfix.1 and later.Show less
1Ui
1Unifi Video
Jun 17, 2026
May 17, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
In Ubiquiti UniFi Video v3.10.13, when the executable starts, its first library validation is in the current directory. This allows the impersonation and modification of the library to execute code on the system. This wa...Show more
In Ubiquiti UniFi Video v3.10.13, when the executable starts, its first library validation is in the current directory. This allows the impersonation and modification of the library to execute code on the system. This was tested in (Windows 7 x64/Windows 10 x64).Show less
1Ui
1Unifi Protect Controller
Jun 17, 2026
Feb 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
UniFi Protect before v1.17.1 allows an attacker to use spoofed cameras to perform a denial-of-service attack that may cause the UniFi Protect controller to crash.
1Ui
2Edgemax Edgepower 24v Firmware
Edgemax Edgepower 54v Firmware
Jun 17, 2026
Dec 14, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have been able to perform unauthorized remote code execution.
1Ui
1Unifi Protect Firmware
Jun 17, 2026
Nov 5, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect controller API was using “x-token” improperly, allowing attackers to use the API to send authenticated m...Show more
A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect controller API was using “x-token” improperly, allowing attackers to use the API to send authenticated messages without a valid token.This vulnerability was fixed in UniFi Protect v1.14.11 and newer.This issue does not impact UniFi Cloud Key Gen 2 plus.This issue does not impact UDM-Pro customers with UniFi Protect stopped.Affected Products:UDM-Pro firmware 1.7.2 and earlier.UNVR firmware 1.3.12 and earlier.Mitigation:Update UniFi Protect to v1.14.11 or newer version; the UniFi Protect controller can be updated through your UniFi OS settings.Alternatively, you can update UNVR and UDM-Pro to:- UNVR firmware to 1.3.15 or newer.- UDM-Pro firmware to 1.8.0 or newer.Show less
1Ui
2Unifi Controller Firmware
Unifi Meshing Access Point Firmware
Jun 17, 2026
Oct 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not erased from an access point returning wirelessly from a disconnected st...Show more
An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not erased from an access point returning wirelessly from a disconnected state. This may provide unintended network access.Show less
1Ui
1Edgemax Firmware
Jun 17, 2026
Aug 21, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be guessed, enabling the attacker to obtain high privileges and get a root shell by...Show more
A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be guessed, enabling the attacker to obtain high privileges and get a root shell by a Command injection.Show less