Skip to content
Auto-CTI
Back to today
NEW CRITICAL A3

[UPDATE] Ubiquiti UniFi OS: Multiple Vulnerabilities

A BSI Warn- und Informationsdienst (WID): Schwachstellen-Informationen (Security Advisories) ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

BSI warning of multiple critical vulnerabilities in Ubiquiti UniFi OS enabling remote code execution and privilege escalation , patches required.

Description

Ubiquiti UniFi OS is vulnerable to multiple weaknesses that allow attackers to execute arbitrary code remotely, disclose confidential information, gain elevated privileges, bypass access controls, and manipulate data. These vulnerabilities compromise the entire network management and access control infrastructure. The BSI has publicly disclosed these vulnerabilities and warns of active or imminent exploitation.

Risk score

51
cvss base
45.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
45.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00
consensus penalty
-3.00

Path: operational

Consensus check

The pipeline self-checks before delivery. These rules lowered the score:

  • TTP_SKIPPED TTP mapping skipped (placeholder or aggregation article) −3
Consensus penalty:
−3.0
Total penalty:
−3.0
ESC