« Volver al listado

UI

UI Unifi OS: vulnerabilidades y CVE

UI Unifi OS tiene 12 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE12
Últimos 12 meses10
Críticas9
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-77550Crítica (10)0.80%—26 ago 2026
A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or…
CVE-2026-77549Crítica (9)0.51%—26 ago 2026
A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to…
CVE-2026-77545Crítica (9)0.39%—26 ago 2026
A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such…
CVE-2026-77540Crítica (9.1)1.3%—26 ago 2026
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.
CVE-2026-77536Crítica (9.9)0.42%—26 ago 2026
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or…
CVE-2026-77534Crítica (9.9)0.42%—26 ago 2026
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or…
CVE-2026-48610Alta (8.1)0.37%—12 jun 2026
Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi…
CVE-2026-47370Crítica (9.9)1.4%—12 jun 2026
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS…
CVE-2026-47369Crítica (9.9)0.48%—12 jun 2026
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or…
CVE-2026-47368Alta (8.6)0.50%—12 jun 2026
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances.
CVE-2025-23091Media (5.9)0.20%—1 feb 2025
An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-middle (MitM) attack during application update.
CVE-2023-31997Crítica (9)0.25%—1 jul 2023
UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2) hosting the UniFi…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation3
  2. T1210 Exploitation of Remote Services3
  3. T1190 Exploit Public-Facing Application2
  4. T1059 Command and Scripting Interpreter1
  5. T1078 Valid Accounts1
  6. T1203 Exploitation for Client Execution1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de UI