CVE-2026-47370
CRITICAL
9.9
CVSS 3.1
Description
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances.
Metadata
Severity & Metrics
9.9
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (32)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Ubiquiti Inc | EFG | — | 0 < 5.1.15 |
| Ubiquiti Inc | ENVR | — | 0 < 5.1.15 |
| Ubiquiti Inc | ENVR-Core | — | 0 < 5.1.15 |
| Ubiquiti Inc | Express | — | 0 < 4.0.15 |
| Ubiquiti Inc | Express 7 | — | 0 < 5.1.15 |
| Ubiquiti Inc | UCG-Fiber | — | 0 < 5.1.15 |
| Ubiquiti Inc | UCG-Industrial | — | 0 < 5.1.15 |
| Ubiquiti Inc | UCG-Max | — | 0 < 5.1.15 |
| Ubiquiti Inc | UCG-Ultra | — | 0 < 5.1.15 |
| Ubiquiti Inc | UCK | — | 0 < 5.1.15 |
| Ubiquiti Inc | UCK-Enterprise | — | 0 < 5.1.15 |
| Ubiquiti Inc | UCKP | — | 0 < 5.1.15 |
| Ubiquiti Inc | UDM | — | 0 < 5.1.15 |
| Ubiquiti Inc | UDM-Beast | — | 0 < 5.1.15 |
| Ubiquiti Inc | UDM-Pro | — | 0 < 5.1.15 |
| Ubiquiti Inc | UDM-Pro-Max | — | 0 < 5.1.15 |
| Ubiquiti Inc | UDM-SE | — | 0 < 5.1.15 |
| Ubiquiti Inc | UDR | — | 0 < 5.1.15 |
| Ubiquiti Inc | UDR-5G | — | 0 < 5.1.15 |
| Ubiquiti Inc | UDR7 | — | 0 < 5.1.15 |
| Ubiquiti Inc | UDW | — | 0 < 5.1.15 |
| Ubiquiti Inc | UNAS-2 | — | 0 < 5.1.16 |
| Ubiquiti Inc | UNAS-4 | — | 0 < 5.1.16 |
| Ubiquiti Inc | UNAS-Pro | — | 0 < 5.1.16 |
| Ubiquiti Inc | UNAS-Pro-4 | — | 0 < 5.1.16 |
| Ubiquiti Inc | UNAS-Pro-8 | — | 0 < 5.1.16 |
| Ubiquiti Inc | UniFi OS Server | — | 0 < 5.1.15 |
| Ubiquiti Inc | UNVR | — | 0 < 5.1.15 |
| Ubiquiti Inc | UNVR-G2 | — | 0 < 5.1.15 |
| Ubiquiti Inc | UNVR-G2-Pro | — | 0 < 5.1.15 |
| Ubiquiti Inc | UNVR-Instant | — | 0 < 5.1.15 |
| Ubiquiti Inc | UNVR-Pro | — | 0 < 5.1.15 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-20 | cna | CWE-20 Improper Input Validation |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.9 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
References (1)