Vulnerabilities

Summary — last 7 days

New vulnerabilities2,865▼ 160 vs. last week
Critical / high1,384▲ 52 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)266▼ 260 vs. last week
–

8 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.5)1.3%—UI Er-x FirmwareUI Er-x-sfp Firmware4/28/20236/17/2026
A vulnerability classified as critical has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown part of the component Web Service. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The…
ModifiedHigh (7.3)7.6%—UI Er-x FirmwareUI Er-x-sfp Firmware4/28/20237/9/2026
A flaw has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown function of the component Web Management Interface. This manipulation of the argument suffix-rate-up causes command injection. The attack may be initiated remotely. The exploit has been published and may be used. The real…
ModifiedHigh (7.3)7.6%—UI Er-x FirmwareUI Er-x-sfp Firmware4/28/20237/9/2026
A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The impacted element is an unknown function of the component Web Management Interface. The manipulation of the argument Name results in command injection. The attack can be launched remotely. The exploit is now public and may be used. There is…
ModifiedHigh (7.3)7.6%—UI Er-x FirmwareUI Er-x-sfp Firmware4/28/20237/9/2026
A security vulnerability has been detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The affected element is an unknown function of the component Web Management Interface. The manipulation of the argument dpi leads to command injection. The attack can be initiated remotely. The exploit has been disclosed publicly…
ModifiedHigh (7.3)9.3%—UI Er-x FirmwareUI Er-x-sfp Firmware4/28/20237/9/2026
A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. Impacted is an unknown function of the component Web Management Interface. Executing a manipulation of the argument src can lead to command injection. It is possible to launch the attack remotely. The exploit has been made available to the…
ModifiedHigh (7.3)6.9%—UI Er-x FirmwareUI Er-x-sfp Firmware4/28/20237/9/2026
A security flaw has been discovered in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This issue affects some unknown processing of the component Web Management Interface. Performing a manipulation of the argument ecn-down results in command injection. It is possible to initiate the attack remotely. The exploit has been…
ModifiedHigh (8.8)0.96%—UI USG FirmwareUI Usg-pro-4 FirmwareUI Er-10x FirmwareUI Er-12 Firmware+62/9/20236/17/2026
A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with their DHCPv6 prefix delegation set to dhcpv6-stateless or dhcpv6-stateful, allows a malicious actor directly connected to the WAN interface of an affected device to create a remote…
ModifiedHigh (7.5)5.1%—UI Er-x FirmwareUI Er-x-sfp FirmwareUI Ep-r6 FirmwareUI Erlite-3 Firmware+89/25/20196/17/2026
Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in /var/run/beaker/container_file/ are created when providing a valid length payload of 249 characters or fewer to the beaker.session.id cookie in a GET header. The attacker can use a long…