Ubiquiti Security Advisories & CVEs
4 advisories tracked · Ubiquiti Security Advisory Bulletins + NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Ubiquiti CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your Ubiquiti device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Ubiquiti's recent advisories.
Official source
Ubiquiti Security Advisory Bulletins + NVD
Ubiquiti publishes Security Advisory Bulletins on its community site (community.ui.com), but there is no machine-readable feed and its CVEs are coordinated through HackerOne rather than a single Ubiquiti CNA — so VulniPulse ingests them from NVD (keyword-filtered to Ubiquiti) and links each CVE back to its community.ui.com bulletin when referenced. Covers UniFi Network / UniFi OS, the Dream Machine line (UDM/UDR/UCG), UniFi Protect, Access, Talk and Connect, plus EdgeRouter, EdgeSwitch, UISP and AmpliFi — an enormous internet-facing prosumer + SMB fleet that repeatedly ships max-severity (CVSS 10.0) flaws.
Latest Ubiquiti advisories
Critical [CVE-2019-25651] Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC…
Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 uses AES-CBC encryption for device-to-controller communication, which contains cryptographic weaknesses that allow attackers to recover encryption keys from captured traffic. Attackers with adjacent network access can capture sufficient encrypted traffic and exploit AES-CBC mode vulnerabilities to derive the encryption keys, enabling unauthorized control and management of network devices. Affected products named by the advisory: UniFi UAP Firmware; UniFi UAP-AC Firmware; UniFi USW Firmware; UniFi USG Firmware.
Critical [CVE-2024-54750] Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which
Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: In Ubiquiti's view there is no vulnerability as the Hardcoded Password should be after setup not before.
Critical [CVE-2023-24104] UniFi: Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.
Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.
Critical [CVE-2010-5330] airMAX: On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info)
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected.