Skip to content
VulniPulse

Ubiquiti UISP / airMAX Vulnerabilities & Security Advisories

4 advisories tracked · Ubiquiti Security Advisory Bulletins + NVD · 1 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Ubiquiti advisory that VulniPulse classified as UISP / airMAX, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 1 high, 2 medium.

Android app · Google Play

Monitor Ubiquiti CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Ubiquiti Security Advisory Bulletins + NVD

Ubiquiti publishes Security Advisory Bulletins on its community site (community.ui.com), but there is no machine-readable feed and its CVEs are coordinated through HackerOne rather than a single Ubiquiti CNA — so VulniPulse ingests them from NVD (keyword-filtered to Ubiquiti) and links each CVE back to its community.ui.com bulletin when referenced. Covers UniFi Network / UniFi OS, the Dream Machine line (UDM/UDR/UCG), UniFi Protect, Access, Talk and Connect, plus EdgeRouter, EdgeSwitch, UISP and AmpliFi — an enormous internet-facing prosumer + SMB fleet that repeatedly ships max-severity (CVSS 10.0) flaws.

Latest Ubiquiti UISP / airMAX advisories

High8.8Ubiquiti

High [CVE-2026-21639] airMAX AC: malicious actor in Wi-Fi range of the affected product

A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product. Affected products named by the advisory: airMAX AC; airMAX M; airFiber AF60-XG; airFiber AF60.

CVE-2026-21639
UISP / airMAX
Jan 8, 2026
Medium6.6Ubiquiti

Medium [CVE-2024-44540] Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell

Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART Debugging Port.

CVE-2024-44540
UISP / airMAX
Sep 23, 2024
Medium5.9Ubiquiti

Medium [CVE-2023-23119] The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes Ubiquiti airFiber AF2X…

The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes Ubiquiti airFiber AF2X Radio firmware version 3.2.2 and earlier vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification.

CVE-2023-23119
UISP / airMAX
Feb 2, 2023
Critical9.8Ubiquiti Exploited CISA KEV

Critical [CVE-2010-5330] airMAX: On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info)

On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected.

CVE-2010-5330
UISP / airMAX
Jun 11, 2019

← All Ubiquiti advisories