UI
UI Unifi Network Application: vulnerabilidades y CVE
UI Unifi Network Application tiene 15 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses9
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-77541 | Crítica (9.1) | 0.46% | — | 26 ago 2026 | A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application. |
| CVE-2026-77535 | Crítica (9.1) | 1.3% | — | 26 ago 2026 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Command Injection on an adopted device. |
| CVE-2026-56842 | Alta (7.5) | 0.36% | — | 2 jul 2026 | A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application… |
| CVE-2026-55118 | Alta (8.3) | 0.37% | — | 2 jul 2026 | A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi… |
| CVE-2026-55114 | Alta (8.8) | 0.47% | — | 2 jul 2026 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application. |
| CVE-2026-54406 | Alta (8.7) | 0.59% | — | 2 jul 2026 | A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device. |
| CVE-2026-54405 | Alta (7.5) | 0.52% | — | 2 jul 2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Denial of Service (DoS) attack on the application. |
| CVE-2026-22558 | Alta (7.7) | 0.55% | — | 19 mar 2026 | An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges. |
| CVE-2026-22557 | Crítica (10) | 28% | — | 19 mar 2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying… |
| CVE-2024-42028 | Alta (8.8) | 0.16% | — | 28 oct 2024 | A Local privilege escalation vulnerability found in a Self-Hosted UniFi Network Server with UniFi Network Application (Version 8.4.62 and earlier) allows a malicious actor with a local operational system user to execute… |
| CVE-2024-42025 | Alta (7.8) | 0.82% | — | 13 sept 2024 | A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) allows a malicious actor with unifi user shell access to escalate… |
| CVE-2024-27981 | Crítica (9.8) | 1.2% | — | 4 abr 2024 | A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with UniFi Network Application Administrator… |
| CVE-2023-41721 | Media (5.3) | 0.59% | — | 25 oct 2023 | Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to… |
| CVE-2023-32000 | Media (4.8) | 0.33% | — | 8 jul 2023 | A Cross-Site Scripting (XSS) vulnerability found in UniFi Network (Version 7.3.83 and earlier) allows a malicious actor with Site Administrator credentials to escalate privileges by persuading an Administrator to visit… |
| CVE-2023-28365 | Crítica (9.1) | 0.76% | — | 1 jul 2023 | A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious commands on the host device being restored. |
Otros productos de UI
Unifi Protect · 21Unifi OS · 12Unifi OS Server · 11Unifi Dream Machine PRO Firmware · 11Unifi Cloud Gateway Industrial Firmware · 10Unifi Cloud Gateway MAX Firmware · 10Unifi Dream Router 7 Firmware · 10Enterprise Network Video Recorder Firmware · 10Unifi Dream Machine PRO MAX Firmware · 10Unifi Cloudkey Firmware · 10Enterprise Network Video Recorder Core Firmware · 10Unifi Cloud Gateway Fiber Firmware · 10