Skip to content
VulniPulse

Ubiquiti Security Advisories & CVEs

24 advisories tracked · Ubiquiti Security Advisory Bulletins + NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Ubiquiti CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Ubiquiti device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Ubiquiti's recent advisories.

Official source

Ubiquiti Security Advisory Bulletins + NVD

Ubiquiti publishes Security Advisory Bulletins on its community site (community.ui.com), but there is no machine-readable feed and its CVEs are coordinated through HackerOne rather than a single Ubiquiti CNA — so VulniPulse ingests them from NVD (keyword-filtered to Ubiquiti) and links each CVE back to its community.ui.com bulletin when referenced. Covers UniFi Network / UniFi OS, the Dream Machine line (UDM/UDR/UCG), UniFi Protect, Access, Talk and Connect, plus EdgeRouter, EdgeSwitch, UISP and AmpliFi — an enormous internet-facing prosumer + SMB fleet that repeatedly ships max-severity (CVSS 10.0) flaws.

Latest Ubiquiti advisories

Critical9.8Ubiquiti Exploited CISA KEV

Critical [CVE-2010-5330] airMAX: On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info)

On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected.

CVE-2010-5330
UISP / airMAX
Jun 11, 2019
High7.2Ubiquiti

High [CVE-2018-5265] Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remote attackers to execute arbitrary code with admin credentials

Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remote attackers to execute arbitrary code with admin credentials, because /opt/vyatta/share/vyatta-cfg/templates/system/static-host-mapping/host-name/node.def does not sanitize the 'alias' or 'ips' parameter for shell metacharacters.

CVE-2018-5265
EdgeRouter / EdgeSwitch
Jun 7, 2019
Medium5.9Ubiquiti

Medium [CVE-2018-5264] Ubiquiti UniFi 52 devices, when Hotspot mode is used

Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free time" Wi-Fi usage by sending a /guest/s/default/ request to obtain a cookie, and then using this cookie in a /guest/s/default/login request with the byfree parameter.

CVE-2018-5264
Unclassified
Jun 7, 2019
High7.5Ubiquiti

High [CVE-2019-12727] On Ubiquiti airCam 3.1.4 devices, a Denial of Service vulnerability exists in the RTSP Service provided by the ubnt-streamer…

On Ubiquiti airCam 3.1.4 devices, a Denial of Service vulnerability exists in the RTSP Service provided by the ubnt-streamer binary. The issue can be triggered via malformed RTSP requests that lead to an invalid memory read. To exploit the vulnerability, an attacker must craft an RTSP request with a large number of headers.

CVE-2019-12727
Unclassified
Jun 4, 2019

← All vendors